Logo Hardware.com.br
Prongss
Prongss Membro Junior Registrado
34 Mensagens 16 Curtidas

[Resolvido] Possível vírus via pendrive.

#1 Por Prongss 22/01/2018 - 13:21
Olá, a mais ou menos 3 dias coloquei o pendrive do meu primo na minha máquina para passar alguns arquivos e assim q eu coloquei notei q não estava funcionando o pendrive, retirei o pendrive dele e coloquei alguns outros meus e vi que as portas não estavam funcionando. Imaginei q fosse algum bug, pois estavam funcionando normalmente antes, só q quando reiniciei o windows, ele parecia estar corrompido, deu uma tela azul com uma carinha triste dizendo q o boot estava inacessível e nenhuma das ferramentas de reparo funcionou, única solução foi a formatação. Achei q tinha um programa eu havia instalado, que baixa vídeos diretamente do youtube, que poderia ter causado o problema pois o Avira havia encontrado uma ameaça durante a instalação, mas no dia seguinte coloquei o pendrive do meu primo novamente no computador e ocorreu o mesmo problema, primeiro falhou as portas usb e quando reiniciei deu a mesma tela azul e tive que formatar novamente. Ele me disse que utilizou esse pendrive no local onde ele trabalha e numa lan house, e como eu ajudava ele constantemente sempre notava que o pendrive estava sempre corrompendo os arquivos do pendrive e eu tinha que formata-lo. Agora minhas duvidas, um possível defeito no pendrive pode ter corrompido o windows ? pode ter sido um vírus ? caso tenha sido um vírus, ele pode ter tido acesso aos meus dados? durante formatação, eu formatei todas as partições existentes, mas não as deletei e criei novamente e também notei a presença de uma partição OEM que não existia, corro risco de ainda estar com o vírus? existe alguma maneira de checar se realmente existiu um vírus ou se ainda esta no pc? Agradeço desde já !!!
joram
joram Highlander Registrado
5.5K Mensagens 2.5K Curtidas
#2 Por joram
22/01/2018 - 14:12
/_ Boa Tarde! Yago passos _\

> Baixe o UsbFix,que é muito eficiente para este tipo de malware.
https://www.fosshub.com/UsbFix.html

> Salve-o ao desktop!
> Clique: "LANÇA UMA ANÁLISE"

Imagem

> Na próxima janela,clique em "ANÁLISE COMPLETA".
> Poste o relatório ao concluir!
Imagem

Imagem
https://www.hardware.com.br/comunidade/v-t/1226830/

Siga as recomendações oficiais deste Tópico e poste: FRST.txt + Addition.txt
Ps: É de suma importância que a FRST.exe,seja baixada ao desktop! (Área de trabalho!)
Disponibilize os relatórios em Cjoint.com ou utilize spoiler,cuja instrução está ao final daquela página.
Outra opçãohospedar os relatórios em Hébergement de fichiers, Security-x.fr.

[Abs]
TmfeijoMMonroe
TmfeijoMMonr... Cyber Highlander Registrado
13.7K Mensagens 4.2K Curtidas
#4 Por TmfeijoMMonr...
22/01/2018 - 14:34
Boa tarde e bem vindo prezado autor !

Rode a família malwarebytes:
Malwarebytes, JRT e o adwcleaner .

https://br.malwarebytes.com/
https://www.bleepingcomputer.com/download/junkware-removal-tool/
https://br.malwarebytes.com/adwcleaner/

Ps: Outro caso bem complexo do que os demais recentemente .
Ps2: Descarte o pen drive; pois temos que salvar o teu pc . Se fosse eu nem injetaria mais este pen . Me ouça; ouve este expert .
Ps3
: Se teu windows for até o 8.0 ; rode o combofix . E todas estas ferramentas rode no modo seguro com rede .

Faça uma por uma; com muita calma e paciência . Ok ?

E finalizando rode a eset on line; assinalando todas as opções em configurações avançadas; que realizaremos um racional feito de limpeza em seu pc .
Removeremos o que nós nem imaginamos que está contido em seu sistema .

https://www.eset.com/br/antivirus-domestico/online-scanner/

Por fineza poste os relatórios.

Abraços

Yago passos disse:
A ignorância é a pior inimiga do homem . Não tenho medo de nada; apenas da inveja . E o mundo cada vez melhor !!
Palavras sábias de um hiper profissional do judiciário; perito digital e em psicologia jurídica .
A sua inveja é a velocidade de meu sucesso .
Um coração medroso congela o trabalho . Um coração temerário incendeia qualquer serviço ; arrasando - o .
Prongss
Prongss Membro Junior Registrado
34 Mensagens 16 Curtidas
#6 Por Prongss
22/01/2018 - 16:10
Estou usando o windows 10 então acho q não posso utilizar o combofix, coloquei o pen drive duas vezes somente e nas duas eu fui forçado a formatar a maquina, depois que descobri que o problema era ele, não tornei a usa-lo, realizei todos os processos da malwarebytes e nenhum acusou alguma ameaça, exceto o adw, que excluiu uma extensão do chrome que era do avira search, que ele identificou como PUP.optional.legacy, não realizei o processo do eset pq realizei o processo de verificação do Avira, caso necessário eu faço no eset tbm. Não sei exatamente como postar o relatório, espero q eu esteja fazendo corretamente.

Anexos

Komm
Komm Cyber Highlander Registrado
12.8K Mensagens 2.7K Curtidas
#7 Por Komm
22/01/2018 - 16:21
Não utilize mais este pendrive. Ponto. Avise ao seu primo o que está acontecendo antes de devolvê-lo.

Já que está aqui, aproveite para fazer a checagem por malwares no micro.
Passe o ZHPCleaner. Depois, poste os logs da FRST que o joram pediu.
https://www.nicolascoolman.com/download/zhpcleaner/

Estes dois são procedimentos rápidos. O escaneamento com o ESET Online Scanner é bem mais demorado.
Fica à sua escolha.

[]s.
Legal mesmo é a cara do cachorro quando a bicicleta para! mostrando_dentes.png
Prongss
Prongss Membro Junior Registrado
34 Mensagens 16 Curtidas
#8 Por Prongss
22/01/2018 - 16:54
Desculpa, acabei não prestando atenção e postando o log de modo incorreto.
Não conseguir utilizar o FRST pois o windows defender esta bloqueando o mesmo, vou botar como spoiler os logs que ja tenho comigo. Creio q agora esteja correto.

"ZHPcleaner"

~ ZHPCleaner v2018.1.19.13 by Nicolas Coolman (2018/01/19)
~ Run by Mário (Administrator) (22/01/2018 16:40:54)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Legal
~ Type : Scan
~ Report : C:\Users\Mário\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Mário\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 16299)


---\\ Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\ Services (0)
~ No malicious or unnecessary items found.


---\\ Browser internet (1)
FOUND Google Chrome Preferences: "https://dnn506yrbagrg.cloudfront.net/" =>.SUP.CloudfrontNet


---\\ Hosts file (1)
~ The hosts file is legitimate (21)


---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\ Explorer ( File, Folder) (5)
FOUND file: C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092\storage\default\https+++onsalus.com.br\.metadata =>PUP.Optional.Salus
FOUND file: C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092\storage\default\https+++onsalus.com.br\.metadata-v2 =>PUP.Optional.Salus
FOUND file: C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092\storage\default\https+++onsalus.com.br\cache\.padding =>PUP.Optional.Salus
FOUND file: C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092\storage\default\https+++onsalus.com.br\cache\caches.sqlite =>PUP.Optional.Salus
FOUND file: C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092\storage\default\https+++onsalus.com.br\cache\morgue\80\{4d7de959-deec-4795-8382-ab908c083050}.final =>PUP.Optional.Salus


---\\ Registry ( Key, Value, Data) (2)
FOUND key: [X64] HKLM\SOFTWARE\Classes\S [] =>Toolbar.Agent
FOUND key: HKLM\SYSTEM\CurrentControlSet\Services\VIAKaraokeService [] =>Trojan.EFGSoft


---\\ Summary of the elements found (4)
https://nicolascoolman.eu/2017/02/02/superfluous-cloudfrontnet/ =>.SUP.CloudfrontNet
https://nicolascoolman.eu/2017/09/07/pup-optional-salus/ =>PUP.Optional.Salus
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>Toolbar.Agent
https://nicolascoolman.eu/2017/10/18/trojan-efgsoft/ =>Trojan.EFGSoft


---\\ Result of repair
~ Any repair made
~ Browser not found (Opera Software)


---\\ Statistics
~ Items scanned : 89359
~ Items found : 8
~ Items cancelled : 0
~ Items options : 0/7
~ Space saving (bytes) : 0


~ End of search in 00h04mn41s
~====================
ZHPCleaner-[S]-22012018-16_45_35.txt
[/S]

[S]
"JRT"

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Pro x64
Ran by M rio (Administrator) on 22/01/2018 at 15:01:22,29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/01/2018 at 15:03:55,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


"ADWcleaner"

# AdwCleaner 7.0.7.0 - Logfile created on Mon Jan 22 16:54:47 2018
# Updated on 2018/18/01 by Malwarebytes
# Running on Windows 10 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

Plugin deleted: Avira SafeSearch Plus -


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [1112 B] - [2018/1/22 16:51:25]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
[/S]

Consegui realizar o exame, aqui estão os logs do FRST.
"FRST"

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 21.01.2018
Executado por Mário (administrador) em DESKTOP-520UTA6 (22-01-2018 16:55:55)
Executando a partir de E:\Yago\COISAS\Arquivos
Perfis Carregados: Mário & (Perfis Disponíveis: Mário)
Platform: Windows 10 Pro Versão 1709 16299.192 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() E:\Yago\COISAS\Arquivos\ZHPCleaner.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2017-12-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 192.168.25.1
Tcpip\..\Interfaces\{96ab84d8-3d1b-4fc5-89d4-4a58ba30dac2}: [DhcpNameServer] 192.168.25.1

Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-01-16] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-01-16] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-16] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-16] (Oracle Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-16] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-16] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-16] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-16] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 8kq7tzy7.default-1516410435092
FF ProfilePath: C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092 [2018-01-22]
FF Extension: (Adblock Plus) - C:\Users\Mário\AppData\Roaming\Mozilla\Firefox\Profiles\8kq7tzy7.default-1516410435092\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-01-19]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-16] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-16] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-16] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-16] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-16] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-16] (Google Inc.)

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1128944 2018-01-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [492560 2018-01-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [492560 2018-01-04] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1526832 2018-01-04] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [444600 2017-12-21] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7761584 2017-12-23] (Microsoft Corporation)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4329952 2017-12-13] (Microsoft Corporation)
R2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [27768 2014-11-20] (VIA Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [60920 2018-01-04] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [178840 2018-01-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [169376 2018-01-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2018-01-04] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2018-01-04] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [38048 2018-01-04] (Avira Operations GmbH & Co. KG)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77432 2017-11-29] ()
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [193968 2018-01-22] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2018-01-22] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [46008 2018-01-22] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2018-01-22] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2018-01-22] (Malwarebytes)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três Meses Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2018-01-22 16:55 - 2018-01-22 16:55 - 000000000 ____D C:\FRST
2018-01-22 16:45 - 2018-01-22 16:45 - 000002825 _____ C:\Users\Mário\Desktop\ZHPCleaner.txt
2018-01-22 16:40 - 2018-01-22 16:45 - 000000000 ____D C:\Users\Mário\AppData\Roaming\ZHP
2018-01-22 16:40 - 2018-01-22 16:40 - 000000875 _____ C:\Users\Mário\Desktop\ZHPCleaner.lnk
2018-01-22 16:40 - 2018-01-22 16:40 - 000000000 ____D C:\Users\Mário\AppData\Local\ZHP
2018-01-22 16:35 - 2018-01-22 16:35 - 003046784 _____ C:\Users\Mário\Downloads\ZHPCleaner.exe
2018-01-22 16:33 - 2018-01-22 16:33 - 002393088 _____ (Farbar) C:\Users\Mário\Downloads\FRST64.exe
2018-01-22 15:56 - 2018-01-22 15:56 - 000003938 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-01-22 15:56 - 2018-01-22 15:56 - 000002870 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-01-22 15:56 - 2018-01-22 15:56 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-01-22 15:56 - 2018-01-22 15:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-01-22 15:56 - 2018-01-22 15:56 - 000000000 ____D C:\Program Files\CCleaner
2018-01-22 15:55 - 2018-01-22 15:55 - 011205832 _____ (Piriform Ltd) C:\Users\Mário\Downloads\ccsetup539.exe
2018-01-22 15:38 - 2018-01-22 15:38 - 005660870 _____ (Swearware) C:\Users\Mário\Downloads\ComboFix.exe
2018-01-22 15:30 - 2018-01-22 15:30 - 006972536 _____ (ESET spol. s r.o.) C:\Users\Mário\Downloads\esetonlinescanner_ptb.exe
2018-01-22 15:30 - 2018-01-22 15:30 - 000000000 ____D C:\Users\Mário\AppData\Local\ESET
2018-01-22 15:22 - 2018-01-22 15:22 - 000001135 _____ C:\Users\Mário\Desktop\AdwCleaner[C0].txt
2018-01-22 15:03 - 2018-01-22 15:03 - 000000546 _____ C:\Users\Mário\Desktop\JRT.txt
2018-01-22 14:58 - 2018-01-22 14:58 - 001790024 _____ (Malwarebytes) C:\Users\Mário\Downloads\JRT.exe
2018-01-22 14:48 - 2018-01-22 14:54 - 000000000 ____D C:\AdwCleaner
2018-01-22 14:47 - 2018-01-22 16:41 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-01-22 14:47 - 2018-01-22 14:56 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-01-22 14:47 - 2018-01-22 14:56 - 000046008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-01-22 14:47 - 2018-01-22 14:47 - 008206624 _____ (Malwarebytes) C:\Users\Mário\Downloads\adwcleaner_7.0.7.0.exe
2018-01-22 14:47 - 2018-01-22 14:47 - 000193968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2018-01-22 14:46 - 2018-01-22 14:56 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-01-22 14:46 - 2018-01-22 14:46 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-01-22 14:46 - 2018-01-22 14:46 - 000000000 ____D C:\Users\Todos os Usuários\Malwarebytes
2018-01-22 14:46 - 2018-01-22 14:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-01-22 14:46 - 2018-01-22 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-22 14:46 - 2018-01-22 14:46 - 000000000 ____D C:\Program Files\Malwarebytes
2018-01-22 14:46 - 2017-11-29 09:11 - 000077432 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2018-01-22 14:44 - 2018-01-22 14:45 - 082654512 _____ (Malwarebytes ) C:\Users\Mário\Downloads\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3747.exe
2018-01-21 19:11 - 2018-01-21 19:11 - 000013433 _____ C:\Users\Mário\Downloads\Ficha de matricula 2 PDF.pdf
2018-01-19 23:07 - 2018-01-19 23:07 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2018-01-19 23:07 - 2018-01-19 23:07 - 000000993 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2018-01-19 23:07 - 2018-01-19 23:07 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-01-19 23:07 - 2018-01-19 23:07 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-01-19 23:06 - 2018-01-19 23:06 - 000311216 _____ (Mozilla) C:\Users\Mário\Downloads\Firefox Installer.exe
2018-01-19 14:08 - 2018-01-19 14:08 - 000000000 ____D C:\Users\Mário\AppData\LocalLow\Temp
2018-01-19 14:07 - 2018-01-19 14:08 - 000300524 _____ C:\Users\Mário\Downloads\Ficha de matricula PDF.pdf
2018-01-18 20:46 - 2018-01-18 20:46 - 000937072 _____ C:\Users\Mário\Downloads\Boleto 24.01.pdf
2018-01-18 09:48 - 2018-01-18 09:48 - 000000000 ____D C:\Users\Mário\AppData\Local\PeerDistRepub
2018-01-18 00:39 - 2018-01-19 07:17 - 000003020 _____ C:\WINDOWS\System32\Tasks\Optimize Push Notification Data File-S-1-5-21-1720934648-1002782208-2448832314-1001
2018-01-17 20:10 - 2017-12-22 11:45 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-01-17 20:10 - 2017-12-22 11:45 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-17 18:16 - 2018-01-17 18:18 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-01-17 18:16 - 2018-01-17 18:16 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-01-17 18:16 - 2018-01-17 18:16 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-01-17 18:03 - 2018-01-01 15:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-01-17 18:03 - 2018-01-01 10:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-01-17 18:03 - 2018-01-01 10:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
2018-01-17 18:03 - 2018-01-01 10:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-01-17 18:03 - 2018-01-01 10:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-01-17 18:03 - 2018-01-01 10:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-01-17 18:03 - 2018-01-01 10:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-01-17 18:03 - 2018-01-01 10:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-01-17 18:03 - 2018-01-01 10:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-01-17 18:03 - 2018-01-01 10:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-01-17 18:03 - 2018-01-01 10:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-01-17 18:03 - 2018-01-01 10:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-01-17 18:03 - 2018-01-01 10:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-01-17 18:03 - 2018-01-01 10:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-01-17 18:03 - 2018-01-01 10:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-01-17 18:03 - 2018-01-01 10:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2018-01-17 18:03 - 2018-01-01 10:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-01-17 18:03 - 2018-01-01 10:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-01-17 18:03 - 2018-01-01 10:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-01-17 18:03 - 2018-01-01 10:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-01-17 18:03 - 2018-01-01 10:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-01-17 18:03 - 2018-01-01 10:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-01-17 18:03 - 2018-01-01 10:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-01-17 18:03 - 2018-01-01 10:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-01-17 18:03 - 2018-01-01 10:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-01-17 18:03 - 2018-01-01 10:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-01-17 18:03 - 2018-01-01 10:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-01-17 18:03 - 2018-01-01 10:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-01-17 18:03 - 2018-01-01 10:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-01-17 18:03 - 2018-01-01 10:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-01-17 18:03 - 2018-01-01 10:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-01-17 18:03 - 2018-01-01 10:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-01-17 18:03 - 2018-01-01 10:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-01-17 18:03 - 2018-01-01 10:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2018-01-17 18:03 - 2018-01-01 09:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-01-17 18:03 - 2018-01-01 09:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-01-17 18:03 - 2018-01-01 09:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-01-17 18:03 - 2018-01-01 09:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-01-17 18:03 - 2018-01-01 09:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-01-17 18:03 - 2018-01-01 09:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-01-17 18:03 - 2018-01-01 09:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-17 18:03 - 2018-01-01 09:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-01-17 18:03 - 2018-01-01 09:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-01-17 18:03 - 2018-01-01 09:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-01-17 18:03 - 2018-01-01 09:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-01-17 18:03 - 2018-01-01 09:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-01-17 18:03 - 2018-01-01 09:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-01-17 18:03 - 2018-01-01 09:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-01-17 18:03 - 2018-01-01 09:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-01-17 18:03 - 2018-01-01 09:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-01-17 18:03 - 2018-01-01 09:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-01-17 18:03 - 2018-01-01 09:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-01-17 18:03 - 2018-01-01 09:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-01-17 18:03 - 2018-01-01 09:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-01-17 18:03 - 2018-01-01 09:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-01-17 18:03 - 2018-01-01 09:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2018-01-17 18:03 - 2018-01-01 09:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-01-17 18:03 - 2018-01-01 09:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-01-17 18:03 - 2018-01-01 09:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-01-17 18:03 - 2018-01-01 09:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-01-17 18:03 - 2018-01-01 09:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-01-17 18:03 - 2018-01-01 09:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2018-01-17 18:03 - 2018-01-01 09:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-01-17 18:03 - 2018-01-01 09:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-01-17 18:03 - 2018-01-01 09:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-01-17 18:03 - 2018-01-01 09:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-01-17 18:03 - 2018-01-01 09:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-01-17 18:03 - 2018-01-01 09:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-01-17 18:03 - 2018-01-01 09:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-01-17 18:03 - 2018-01-01 09:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2018-01-17 18:03 - 2018-01-01 09:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-01-17 18:03 - 2018-01-01 09:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-01-17 18:03 - 2018-01-01 09:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-01-17 18:03 - 2018-01-01 09:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-01-17 18:03 - 2018-01-01 09:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-17 18:03 - 2018-01-01 09:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-01-17 18:03 - 2018-01-01 09:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-01-17 18:03 - 2018-01-01 09:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-01-17 18:03 - 2018-01-01 09:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-01-17 18:03 - 2018-01-01 09:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-01-17 18:03 - 2018-01-01 09:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-01-17 18:03 - 2018-01-01 09:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-01-17 18:03 - 2018-01-01 09:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-01-17 18:03 - 2018-01-01 09:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-01-17 18:03 - 2018-01-01 09:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-01-17 18:03 - 2018-01-01 09:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-01-17 18:03 - 2018-01-01 09:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-01-17 18:03 - 2018-01-01 09:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2018-01-17 18:02 - 2018-01-01 10:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-01-17 18:02 - 2018-01-01 10:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-01-17 18:02 - 2018-01-01 10:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2018-01-17 18:02 - 2018-01-01 10:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-01-17 18:02 - 2018-01-01 10:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-01-17 18:02 - 2018-01-01 10:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-01-17 18:02 - 2018-01-01 10:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-01-17 18:02 - 2018-01-01 10:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-01-17 18:02 - 2018-01-01 10:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-01-17 18:02 - 2018-01-01 10:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-01-17 18:02 - 2018-01-01 10:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-01-17 18:02 - 2018-01-01 10:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-01-17 18:02 - 2018-01-01 10:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-01-17 18:02 - 2018-01-01 10:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-01-17 18:02 - 2018-01-01 10:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-01-17 18:02 - 2018-01-01 10:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-01-17 18:02 - 2018-01-01 10:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-01-17 18:02 - 2018-01-01 10:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2018-01-17 18:02 - 2018-01-01 10:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2018-01-17 18:02 - 2018-01-01 10:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-01-17 18:02 - 2018-01-01 10:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-01-17 18:02 - 2018-01-01 10:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-01-17 18:02 - 2018-01-01 10:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2018-01-17 18:02 - 2018-01-01 10:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-01-17 18:02 - 2018-01-01 10:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-01-17 18:02 - 2018-01-01 10:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-01-17 18:02 - 2018-01-01 10:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-01-17 18:02 - 2018-01-01 10:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-01-17 18:02 - 2018-01-01 10:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2018-01-17 18:02 - 2018-01-01 10:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2018-01-17 18:02 - 2018-01-01 10:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-01-17 18:02 - 2018-01-01 10:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-01-17 18:02 - 2018-01-01 10:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2018-01-17 18:02 - 2018-01-01 10:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2018-01-17 18:02 - 2018-01-01 10:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-01-17 18:02 - 2018-01-01 10:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-01-17 18:02 - 2018-01-01 10:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-01-17 18:02 - 2018-01-01 10:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-01-17 18:02 - 2018-01-01 10:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-01-17 18:02 - 2018-01-01 10:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-01-17 18:02 - 2018-01-01 10:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-01-17 18:02 - 2018-01-01 10:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2018-01-17 18:02 - 2018-01-01 10:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-01-17 18:02 - 2018-01-01 10:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2018-01-17 18:02 - 2018-01-01 10:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-01-17 18:02 - 2018-01-01 10:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-01-17 18:02 - 2018-01-01 10:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-01-17 18:02 - 2018-01-01 10:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-01-17 18:02 - 2018-01-01 09:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-01-17 18:02 - 2018-01-01 09:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-01-17 18:02 - 2018-01-01 09:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-17 18:02 - 2018-01-01 09:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2018-01-17 18:02 - 2018-01-01 09:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-01-17 18:02 - 2018-01-01 09:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-01-17 18:02 - 2018-01-01 09:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-01-17 18:02 - 2018-01-01 09:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-01-17 18:02 - 2018-01-01 09:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-01-17 18:02 - 2018-01-01 09:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2018-01-17 18:02 - 2018-01-01 09:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2018-01-17 18:02 - 2018-01-01 09:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2018-01-17 18:02 - 2018-01-01 09:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-01-17 18:02 - 2018-01-01 09:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2018-01-17 18:02 - 2018-01-01 09:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-01-17 18:02 - 2018-01-01 09:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2018-01-17 18:02 - 2018-01-01 09:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-01-17 18:02 - 2018-01-01 09:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
2018-01-17 18:02 - 2018-01-01 09:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-01-17 18:02 - 2018-01-01 09:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2018-01-17 18:02 - 2018-01-01 09:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2018-01-17 18:02 - 2018-01-01 09:22 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rfxvmt.dll
2018-01-17 18:02 - 2018-01-01 09:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-17 18:02 - 2018-01-01 09:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-01-17 18:02 - 2018-01-01 09:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2018-01-17 18:02 - 2018-01-01 09:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-01-17 18:02 - 2018-01-01 09:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2018-01-17 18:02 - 2018-01-01 09:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2018-01-17 18:02 - 2018-01-01 09:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2018-01-17 18:02 - 2018-01-01 09:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
2018-01-17 18:02 - 2018-01-01 09:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2018-01-17 18:02 - 2018-01-01 09:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2018-01-17 18:02 - 2018-01-01 09:21 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-01-17 18:02 - 2018-01-01 09:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2018-01-17 18:02 - 2018-01-01 09:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-01-17 18:02 - 2018-01-01 09:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2018-01-17 18:02 - 2018-01-01 09:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2018-01-17 18:02 - 2018-01-01 09:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-01-17 18:02 - 2018-01-01 09:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-01-17 18:02 - 2018-01-01 09:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-01-17 18:02 - 2018-01-01 09:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2018-01-17 18:02 - 2018-01-01 09:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2018-01-17 18:02 - 2018-01-01 09:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-01-17 18:02 - 2018-01-01 09:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-01-17 18:02 - 2018-01-01 09:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-01-17 18:02 - 2018-01-01 09:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-01-17 18:02 - 2018-01-01 09:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-01-17 18:02 - 2018-01-01 09:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-01-17 18:02 - 2018-01-01 09:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-01-17 18:02 - 2018-01-01 09:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-01-17 18:02 - 2018-01-01 09:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-01-17 18:02 - 2018-01-01 09:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-01-17 18:02 - 2018-01-01 09:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-01-17 18:02 - 2018-01-01 09:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-01-17 18:02 - 2018-01-01 09:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-01-17 18:02 - 2018-01-01 09:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-01-17 18:02 - 2018-01-01 09:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-01-17 18:02 - 2018-01-01 09:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2018-01-17 18:02 - 2018-01-01 09:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2018-01-17 18:02 - 2018-01-01 09:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-01-17 18:02 - 2018-01-01 09:11 - 001955328 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSvc.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-01-17 18:02 - 2018-01-01 09:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-01-17 18:02 - 2018-01-01 09:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-01-17 18:02 - 2018-01-01 09:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-01-17 18:02 - 2018-01-01 09:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2018-01-17 18:02 - 2018-01-01 09:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-01-17 18:02 - 2018-01-01 09:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-01-17 18:02 - 2018-01-01 09:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-01-17 18:02 - 2018-01-01 09:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-01-17 18:02 - 2018-01-01 09:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2018-01-17 18:02 - 2018-01-01 09:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2018-01-17 18:02 - 2018-01-01 09:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-01-17 18:02 - 2018-01-01 09:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-01-17 18:02 - 2018-01-01 09:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-01-17 08:24 - 2018-01-17 08:24 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-01-16 21:29 - 2017-08-29 07:23 - 000017894 _____ C:\Users\Mário\Desktop\Planilha do TAXI (2).xlsx
2018-01-16 21:08 - 2018-01-16 21:10 - 000000000 ____D C:\Users\Mário\AppData\Local\PlaceholderTileLogoFolder
2018-01-16 20:26 - 2018-01-16 20:26 - 000000000 ____D C:\Users\Mário\AppData\Roaming\Skype
2018-01-16 20:24 - 2018-01-16 20:24 - 000002536 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002525 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002490 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002474 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002461 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2018-01-16 20:24 - 2018-01-16 20:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office 2016
2018-01-16 19:37 - 2018-01-17 08:44 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-01-16 19:37 - 2018-01-16 19:37 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-01-16 19:33 - 2018-01-16 19:34 - 004369696 _____ (Microsoft Corporation) C:\Users\Mário\Downloads\setupo365proplusretail.x86.pt-br_b_64_.exe
2018-01-16 19:25 - 2018-01-16 19:25 - 000000000 ____D C:\Users\Mário\Documents\League of Legends
2018-01-16 18:51 - 2018-01-16 18:51 - 000000000 ____D C:\Users\Mário\AppData\Roaming\Sun
2018-01-16 18:51 - 2018-01-16 18:51 - 000000000 ____D C:\Users\Mário\AppData\LocalLow\Sun
2018-01-16 18:50 - 2018-01-16 19:00 - 000000000 ____D C:\Users\Todos os Usuários\Oracle
2018-01-16 18:50 - 2018-01-16 19:00 - 000000000 ____D C:\ProgramData\Oracle
2018-01-16 18:50 - 2018-01-16 18:50 - 000097344 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2018-01-16 18:50 - 2018-01-16 18:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-01-16 18:50 - 2018-01-16 18:50 - 000000000 ____D C:\Program Files (x86)\Java
2018-01-16 18:48 - 2018-01-16 18:48 - 000000000 ____D C:\Users\Mário\AppData\Roaming\Macromedia
2018-01-16 18:47 - 2018-01-16 19:00 - 000000000 ____D C:\Users\Mário\AppData\Local\Adobe
2018-01-16 18:47 - 2018-01-16 18:47 - 001861696 _____ (Oracle Corporation) C:\Users\Mário\Downloads\JavaSetup8u161.exe
2018-01-16 18:30 - 2018-01-16 18:30 - 000000000 ____D C:\Users\Todos os Usuários\Riot Games
2018-01-16 18:30 - 2018-01-16 18:30 - 000000000 ____D C:\Users\Mário\AppData\Local\CEF
2018-01-16 18:30 - 2018-01-16 18:30 - 000000000 ____D C:\ProgramData\Riot Games
2018-01-16 18:28 - 2018-01-16 18:28 - 000000741 _____ C:\Users\Public\Desktop\League of Legends.lnk
2018-01-16 18:28 - 2018-01-16 18:28 - 000000000 ____D C:\Riot Games
2018-01-16 18:28 - 2018-01-16 18:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2018-01-16 18:28 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2018-01-16 18:28 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2018-01-16 18:28 - 2008-07-12 08:18 - 003851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2018-01-16 18:28 - 2008-07-12 08:18 - 001493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2018-01-16 18:28 - 2008-07-12 08:18 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2018-01-16 18:24 - 2018-01-16 18:25 - 073046184 _____ (Riot Games, Inc) C:\Users\Mário\Downloads\League of Legends installer BR.exe
2018-01-16 17:47 - 2018-01-16 17:47 - 000002346 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-16 17:47 - 2018-01-16 17:47 - 000002334 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-01-16 17:46 - 2018-01-16 17:55 - 000000000 ____D C:\Users\Mário\AppData\Local\Google
2018-01-16 17:46 - 2018-01-16 17:47 - 000000000 ____D C:\Program Files (x86)\Google
2018-01-16 17:46 - 2018-01-16 17:46 - 000003586 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-01-16 17:46 - 2018-01-16 17:46 - 000003462 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-01-16 17:37 - 2018-01-16 17:37 - 001129816 _____ (Google Inc.) C:\Users\Mário\Downloads\ChromeSetup.exe
2018-01-16 17:33 - 2018-01-16 16:49 - 000000000 ____D C:\Windows.old
2018-01-16 17:28 - 2018-01-16 17:28 - 000003374 _____ C:\WINDOWS\System32\Tasks\Avira_Antivirus_Systray
2018-01-16 17:28 - 2018-01-16 17:28 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2018-01-16 17:28 - 2018-01-16 17:28 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2018-01-16 17:27 - 2018-01-22 16:46 - 000000000 ____D C:\Users\Mário\AppData\LocalLow\Mozilla
2018-01-16 17:27 - 2018-01-16 17:31 - 000000000 ____D C:\Users\Mário\AppData\Local\Mozilla
2018-01-16 17:27 - 2018-01-16 17:27 - 000000000 ____D C:\Users\Mário\AppData\Roaming\Mozilla
2018-01-16 17:27 - 2018-01-04 13:17 - 000178840 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2018-01-16 17:27 - 2018-01-04 13:17 - 000169376 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2018-01-16 17:27 - 2018-01-04 13:17 - 000088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2018-01-16 17:27 - 2018-01-04 13:17 - 000060920 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avdevprot.sys
2018-01-16 17:27 - 2018-01-04 13:17 - 000044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2018-01-16 17:27 - 2018-01-04 13:17 - 000038048 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2018-01-16 17:23 - 2018-01-16 17:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2018-01-16 17:23 - 2018-01-16 17:27 - 000000000 ____D C:\Users\Todos os Usuários\Avira
2018-01-16 17:23 - 2018-01-16 17:27 - 000000000 ____D C:\ProgramData\Avira
2018-01-16 17:23 - 2018-01-16 17:27 - 000000000 ____D C:\Program Files (x86)\Avira
2018-01-16 17:23 - 2018-01-16 17:23 - 000001269 _____ C:\Users\Public\Desktop\Avira.lnk
2018-01-16 17:23 - 2018-01-16 17:23 - 000000000 ____D C:\Users\Todos os Usuários\Package Cache
2018-01-16 17:23 - 2018-01-16 17:23 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-16 17:20 - 2018-01-16 17:20 - 000000000 ____D C:\Users\Todos os Usuários\Microsoft OneDrive
2018-01-16 17:20 - 2018-01-16 17:20 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-01-16 17:18 - 2018-01-17 20:10 - 000000000 ___RD C:\Users\Mário\3D Objects
2018-01-16 17:18 - 2018-01-16 17:18 - 000000000 ___HD C:\Users\Mário\MicrosoftEdgeBackups
2018-01-16 17:18 - 2018-01-16 17:18 - 000000000 ____D C:\Users\Mário\AppData\Local\MicrosoftEdge
2018-01-16 17:18 - 2018-01-16 17:18 - 000000000 ____D C:\Users\Mário\AppData\Local\DBG
2018-01-16 17:17 - 2018-01-22 14:56 - 000000000 __SHD C:\Users\Mário\IntelGraphicsProfiles
2018-01-16 17:17 - 2018-01-16 17:17 - 000000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2018-01-16 17:17 - 2018-01-16 17:17 - 000000020 ___SH C:\Users\Mário\ntuser.ini
2018-01-16 16:54 - 2018-01-16 16:54 - 000000000 ____D C:\Users\Todos os Usuários\USOShared
2018-01-16 16:54 - 2018-01-16 16:54 - 000000000 ____D C:\ProgramData\USOShared
2018-01-16 16:49 - 2018-01-22 15:03 - 001859470 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-16 16:47 - 2018-01-22 14:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-16 16:47 - 2018-01-19 14:30 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1720934648-1002782208-2448832314-1001
2018-01-16 16:47 - 2018-01-16 16:47 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2018-01-16 16:47 - 2018-01-16 16:47 - 000007623 _____ C:\WINDOWS\diagerr.xml
2018-01-16 16:46 - 2018-01-16 16:46 - 000022956 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-01-16 16:43 - 2018-01-16 16:43 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-01-16 16:39 - 2018-01-16 21:31 - 000000000 ____D C:\Users\Mário\AppData\Local\Packages
2018-01-16 16:39 - 2017-09-29 11:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-01-16 16:38 - 2018-01-22 00:58 - 000000000 ____D C:\Users\Mário
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Modelos
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Meus Documentos
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Menu Iniciar
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Documents\Minhas Músicas
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Documents\Minhas Imagens
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Documents\Meus Vídeos
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Dados de Aplicativos
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Configurações Locais
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\AppData\Local\Histórico
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\AppData\Local\Dados de Aplicativos
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Ambiente de Rede
2018-01-16 16:38 - 2018-01-16 16:38 - 000000000 _SHDL C:\Users\Mário\Ambiente de Impressão
2018-01-16 16:38 - 2016-05-03 23:30 - 000081416 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2018-01-16 16:36 - 2018-01-21 18:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-16 16:36 - 2018-01-17 20:09 - 000402920 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-16 16:20 - 2018-01-16 17:34 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-01-16 16:16 - 2018-01-16 16:20 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-01-16 16:04 - 2018-01-16 16:04 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-01-16 15:19 - 2018-01-16 16:49 - 000000000 ___DC C:\WINDOWS\Panther
2018-01-16 15:17 - 2018-01-16 15:19 - 000000036 _____ C:\WINDOWS\progress.ini
2018-01-16 14:43 - 2018-01-16 14:43 - 000000000 ____D C:\Users\Mário\AppData\Local\Comms
2018-01-16 14:32 - 2018-01-16 16:20 - 000000000 ____D C:\WINDOWS\system32\SRSLabs
2018-01-16 14:32 - 2018-01-16 16:20 - 000000000 ____D C:\Program Files\VIA
2018-01-16 14:30 - 2018-01-16 16:20 - 000000000 ____D C:\Program Files\Intel
2018-01-16 14:30 - 2018-01-16 14:30 - 000000000 ____D C:\Program Files (x86)\Intel
2018-01-16 14:30 - 2018-01-16 14:30 - 000000000 ____D C:\Intel
2018-01-16 14:28 - 2018-01-19 14:30 - 000002373 _____ C:\Users\Mário\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-01-16 14:28 - 2018-01-19 14:30 - 000000000 ___RD C:\Users\Mário\OneDrive
2018-01-16 14:28 - 2018-01-16 16:49 - 000000000 ___HD C:\$GetCurrent
2018-01-16 14:25 - 2018-01-17 20:10 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-16 14:25 - 2018-01-16 17:18 - 000000000 ____D C:\Users\Mário\AppData\Local\TileDataLayer
2018-01-16 14:25 - 2018-01-16 15:32 - 000000000 ____D C:\Users\Mário\AppData\Local\Publishers
2018-01-16 14:25 - 2018-01-16 14:25 - 000000000 ____D C:\Users\Mário\AppData\Roaming\Adobe
2018-01-16 14:25 - 2018-01-16 14:25 - 000000000 ____D C:\Users\Mário\AppData\Local\VirtualStore
2018-01-16 14:25 - 2018-01-16 14:25 - 000000000 ____D C:\Users\Mário\AppData\Local\ConnectedDevicesPlatform
2018-01-16 14:20 - 2018-01-16 14:20 - 000000000 ___SD C:\WINDOWS\UpdateAssistantV2
2018-01-16 14:18 - 2018-01-16 14:18 - 000000000 ____D C:\WINDOWS\CSC
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Músicas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Imagens
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus Vídeos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de Aplicativos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Usuário Padrão
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Todos os Usuários\Modelos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Todos os Usuários\Documentos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Todos os Usuários\Dados de Aplicativos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Todos os Usuários
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Public\Documents\Minhas Músicas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Public\Documents\Minhas Imagens
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Public\Documents\Meus Vídeos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Modelos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Meus Documentos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Menu Iniciar
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Documents\Minhas Músicas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Documents\Minhas Imagens
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Documents\Meus Vídeos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Dados de Aplicativos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Configurações Locais
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\AppData\Local\Histórico
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Ambiente de Rede
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default\Ambiente de Impressão
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default User\Documents\Minhas Músicas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default User\Documents\Minhas Imagens
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default User\Documents\Meus Vídeos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Histórico
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Dados de Aplicativos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\ProgramData\Modelos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\ProgramData\Menu Iniciar
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\ProgramData\Documentos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\ProgramData\Dados de Aplicativos
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Program Files\Common Files\Sistema
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Program Files\Arquivos Comuns
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Documents and Settings
2018-01-16 14:16 - 2018-01-16 14:16 - 000000000 _SHDL C:\Arquivos de Programas
2018-01-16 14:12 - 2018-01-16 14:12 - 000000000 _____ C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-12-13 21:29 - 2017-12-13 21:29 - 000000000 ____D C:\WINDOWS\containers
2017-12-13 21:28 - 2017-12-13 21:28 - 021754368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 017159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 017084416 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 013703168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 007545344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 006791472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 006466048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 006015200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 004814848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 004772352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 004592640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 004504456 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 004249600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 003578368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 003478016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 003331520 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 003186688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 003010720 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002972672 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002890240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002783744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002717392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002666496 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002596352 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 002573208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 002491112 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002465848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002446744 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002412168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002393600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002339296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002269080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002220952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002117632 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 002105856 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 001990160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001980928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001970520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001925296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001806336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001778584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001776272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001739264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001694224 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001670656 _____ (Microsoft Corporation) C:\WINDOWS\system32\batmeter.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001666048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001664000 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\batmeter.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001642520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001636376 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001634288 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001628056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001585376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 001558856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001554216 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001528904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001522176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001507736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001490840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001490328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001488792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001474680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001463856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001454568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001432816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001425408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001420696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001377080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001323840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001289216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001280000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001261864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001259344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001148216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001145104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001124760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001057824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001054280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001015008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001012120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001003104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000979352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000975872 _____ C:\WINDOWS\system32\FaceProcessor.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000899584 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000891800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000841728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000840440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000831384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000823808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000819096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000813976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000791960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000769096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcrt.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000768512 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000749976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000747416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000746904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000744856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000739696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000721592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000710912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000705944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000703536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000669592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000666112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000661664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000660480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000654048 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000645528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000640512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000630752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcrt.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000612760 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000610712 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000597160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000592280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000591872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000590944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000566272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000559616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000555416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2017-12-13 21:28 - 2017-12-13 21:28 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000534528 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000525208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000506256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000495000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000474112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000464408 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000442880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000437144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-12-13 21:28 - 2017-12-13 21:28 - 000436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000418712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000404888 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000401304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000373656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000362176 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000361984 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000354200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000353848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000353688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000351232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000293888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000285080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000269696 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000264040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\PushToInstall.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000246168 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000242176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000230296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000198888 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000187288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcui.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ContentDeliveryManager.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000149400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000137544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000136704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gamingtcui.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000101376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-13 21:28 - 2017-12-13 21:28 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000097144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\hascsp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\acppage.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\acppage.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CapabilityAccessManagerClient.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000060824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\urscx01000.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadjcsp.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000048112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KeyboardFilterShim.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdrleakdiag.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000045464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdrleakdiag.exe
2017-12-13 21:28 - 2017-12-13 21:28 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-12-13 21:28 - 2017-12-13 21:28 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcVSp1res.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcVSp1res.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll

==================== Três Meses Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2018-01-22 15:03 - 2017-09-30 12:30 - 000782176 _____ C:\WINDOWS\system32\prfh0416.dat
2018-01-22 15:03 - 2017-09-30 12:30 - 000175120 _____ C:\WINDOWS\system32\prfc0416.dat
2018-01-22 14:55 - 2017-09-29 06:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-01-22 09:02 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-20 09:21 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-01-20 09:20 - 2017-09-29 11:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-19 18:49 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\rescache
2018-01-18 09:52 - 2017-09-29 11:44 - 000000000 ____D C:\WINDOWS\INF
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-01-17 20:06 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-01-17 20:06 - 2017-09-29 06:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-17 20:05 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-01-17 20:05 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2018-01-17 18:16 - 2017-09-29 11:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-17 18:07 - 2017-09-29 11:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-01-17 18:06 - 2017-09-29 11:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-01-17 18:06 - 2017-09-29 11:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-01-17 11:03 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-01-17 08:27 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\appcompat
2018-01-16 20:25 - 2017-09-29 11:46 - 000000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft
2018-01-16 20:25 - 2017-09-29 11:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-01-16 19:37 - 2017-09-29 11:46 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-01-16 18:48 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-01-16 18:48 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-01-16 17:35 - 2017-09-29 11:46 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-01-16 17:34 - 2017-09-29 11:46 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-01-16 17:34 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-01-16 17:34 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\system32\spool
2018-01-16 17:34 - 2017-03-18 19:03 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-01-16 17:33 - 2017-09-29 11:49 - 000000000 ____D C:\WINDOWS\Setup
2018-01-16 16:48 - 2017-09-29 11:46 - 000000000 ____D C:\Users\Todos os Usuários\USOPrivate
2018-01-16 16:48 - 2017-09-29 11:46 - 000000000 ____D C:\ProgramData\USOPrivate
2018-01-16 16:48 - 2017-09-29 11:46 - 000000000 ____D C:\Program Files\windows nt
2018-01-16 16:47 - 2017-09-29 11:46 - 000000000 ____D C:\WINDOWS\Registration
2018-01-16 16:47 - 2017-09-29 06:45 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-01-16 16:46 - 2017-09-29 11:46 - 000000000 __RHD C:\Users\Public\Libraries
2018-01-16 16:40 - 2017-09-29 11:46 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-01-16 16:38 - 2017-09-29 06:45 - 000000000 ____D C:\WINDOWS\system32\Sysprep

==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

LastRegBack: 2018-01-16 16:36

==================== Fim de FRST.txt ============================

"Additon"

Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 21.01.2018
Executado por Mário (22-01-2018 16:57:10)
Executando a partir de E:\Yago\COISAS\Arquivos
Windows 10 Pro Versão 1709 16299.192 (X64) (2018-01-16 18:49:37)
Modo da Inicialização: Normal
==========================================================


==================== Contas: =============================

Administrador (S-1-5-21-1720934648-1002782208-2448832314-500 - Administrator - Disabled)
Convidado (S-1-5-21-1720934648-1002782208-2448832314-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1720934648-1002782208-2448832314-503 - Limited - Disabled)
Mário (S-1-5-21-1720934648-1002782208-2448832314-1001 - Administrator - Enabled) => C:\Users\Mário
WDAGUtilityAccount (S-1-5-21-1720934648-1002782208-2448832314-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Avira (HKLM-x32\...\{518c54f5-fd43-4aa6-936b-8d7fd8c85cbd}) (Version: 1.2.103.26908 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{E3F659C3-7936-4321-B886-4DA527DA72FE}) (Version: 1.2.103.26908 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.34.17 - Avira Operations GmbH & Co. KG)
CCleaner (HKLM\...\CCleaner) (Version: 5.39 - Piriform)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Malwarebytes versão 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft Office 365 ProPlus - pt-br (HKLM\...\O365ProPlusRetail - pt-br) (Version: 16.0.8431.2153 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1720934648-1002782208-2448832314-1001\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1720934648-1002782208-2448832314-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01222018164146914\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation)
Mozilla Firefox 57.0.4 (x64 pt-BR) (HKLM\...\Mozilla Firefox 57.0.4 (x64 pt-BR)) (Version: 57.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.4 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8431.2153 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2153 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2153 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0416-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden

==================== Exame Personalizado CLSID (Whitelisted): ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

CustomCLSID: HKU\S-1-5-21-1720934648-1002782208-2448832314-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-01-04] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-01-04] (Avira Operations GmbH & Co. KG)

==================== Tarefas Agendadas (Whitelisted) =============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {415832A3-6A44-4390-A4CA-A6874E7BCD4B} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-1720934648-1002782208-2448832314-1001
Task: {4227FA95-BB1F-42BD-B620-CF645533984B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-12-23] (Microsoft Corporation)
Task: {466FFC10-529E-44A6-9B1B-9E26B5992A73} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2018-01-04] (Avira Operations GmbH & Co. KG)
Task: {46BF7187-58FD-4DE4-BD7B-CE19D7DD53C9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-16] (Google Inc.)
Task: {4DB5D769-E833-44E4-88D9-A8092F646F8D} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-16] ()
Task: {56441AA5-6818-4D35-8FB4-0DB5B3BB07D4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-01-16] (Microsoft Corporation)
Task: {58C7BE49-8EA4-4EF1-A3FA-F3BBDE6AD3C0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-01-16] (Microsoft Corporation)
Task: {84826BE1-0314-42BA-8211-FBADB2745CBB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-16] (Google Inc.)
Task: {93C5DBE6-C749-40B9-89E7-FC0BEB87AA2D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-01-09] (Piriform Ltd)
Task: {A44A10A8-EC54-46AB-8ABB-6CADEBCA7D06} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-12-23] (Microsoft Corporation)
Task: {B73F10CE-E207-4A9F-BC79-F1445DF601B7} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-01-16] (Microsoft Corporation)
Task: {EA02CF06-3D35-4D08-8A3D-341EDA5D6EA3} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-01-09] (Piriform Ltd)
Task: {FB41D667-27F2-4D88-A9C2-AA0A5EE19873} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-16] ()

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)


==================== Atalhos & WMI ========================

(As entradas podem ser listadas para serem restauradas ou removidas.)


==================== Módulos Carregados (Whitelisted) ==============

2017-09-29 11:41 - 2017-09-29 11:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-01-22 14:46 - 2017-11-29 09:11 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-01-22 14:46 - 2017-11-29 09:11 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-13 21:28 - 2017-12-13 21:28 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-19 11:42 - 2018-01-19 11:42 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-01-19 11:42 - 2018-01-19 11:42 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-01-19 11:42 - 2018-01-19 11:43 - 024677376 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-01-16 15:06 - 2018-01-16 15:07 - 002550272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\skypert.dll
2018-01-22 16:36 - 2018-01-22 16:35 - 003046784 _____ () E:\Yago\COISAS\Arquivos\ZHPCleaner.exe

==================== Alternate Data Streams (Whitelisted) =========

(Se uma entrada for incluída na fixlist, somente o ADS será removido.)


==================== Modo de Segurança (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Associação (Whitelisted) ===============

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.)


==================== Internet Explorer confiável/restrito ===============

(Se uma entrada for incluída na fixlist, será removida do Registro.)


==================== Hosts Conteúdo: ===============================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2017-03-18 19:03 - 2017-03-18 19:01 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Outras Áreas ============================

(Atualmente não há nenhuma correção automática para esta seção.)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01222018164145799\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01222018164146380\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1720934648-1002782208-2448832314-1001\Control Panel\Desktop\\Wallpaper -> E:\Yago\COISAS\outras coisas\imagens\Papel de parede\18817754_1325369374227780_1394723589_o.png
HKU\S-1-5-21-1720934648-1002782208-2448832314-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01222018164146914\Control Panel\Desktop\\Wallpaper -> E:\Yago\COISAS\outras coisas\imagens\Papel de parede\18817754_1325369374227780_1394723589_o.png
DNS Servers: 192.168.25.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Firewall do Windows está habilitado.

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==


==================== Regras do Firewall (Whitelisted) ===============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [{F19BE4FB-F4A6-46F9-BD98-E384AD35599D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{84C9B9B7-F986-49C4-9B4A-FB34EDCCB096}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{0B8717BD-A950-4359-B27E-7D13ED907A07}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{80BCB2B1-1DD4-4434-A840-ADBD095DA084}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{C3755671-95A7-4C70-8011-141930EB53E8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{404862EE-FB49-4F83-964E-10F10381A4B8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{8A19590E-8019-456A-A666-34DBF6B44817}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{676F23FF-745E-4E5E-A7A7-5A219A4559FB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{241518C7-B53B-4A64-B9AF-DC3905032547}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{BA9291F0-23A2-4987-A17C-9485E17E76C6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{2A9639EF-0403-4554-A709-FAAB707E2B60}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{3C305525-0E78-4D0E-B0C4-4B9D34298BA4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{7F57A22B-B447-4C0F-B937-55D37DB0647A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{31A00096-7F36-469B-B922-C4A9248EB453}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{5ED0579A-6F4C-4882-92C7-28A1CF8ED023}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{4AB39C1E-FFBF-48E7-A687-4D60823F382B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
FirewallRules: [{58E6C304-5C4F-438A-93C4-37D29E795CCF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.72.117.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe

==================== Pontos de Restauração =========================

16-01-2018 18:28:16 DirectX instalado
22-01-2018 15:01:24 JRT Pre-Junkware Removal

==================== Dispositivos Apresentando Falhas No Gerenciador =============


==================== Erros no Log de eventos: =========================

Erros em Aplicativos:
==================
Error: (01/17/2018 06:18:47 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Falha no Procedimento Open para o serviço "BITS" na DLL "C:\Windows\System32\bitsperf.dll". Os dados de desempenho para este serviço não estarão disponíveis. Os primeiros quatro bytes (DWORD) da seção de Dados contêm o código do erro.

Error: (01/16/2018 08:26:25 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Erro no arquivo de manifesto ou de política C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL", na linha 1.
Identidade do componente localizado no manifesto não corresponde à identidade do componente solicitado.
A referência é UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
A definição é UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Use o arquivo sxstrace.exe para obter um dignóstico detalhado.

Error: (01/16/2018 06:00:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: ShellExperienceHost.exe, versão: 10.0.16299.15, carimbo de data/hora: 0x59cda974
Nome do módulo com falha: twinapi.appcore.dll, versão: 10.0.16299.19, carimbo de data/hora: 0x63553d36
Código de exceção: 0xc000027b
Deslocamento da falha: 0x0000000000094ef5
ID do processo com falha: 0xfac
Hora de início do aplicativo com falha: 0x01d38efec70873c8
Caminho do aplicativo com falha: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
Caminho do módulo com falha: C:\Windows\System32\twinapi.appcore.dll
ID do Relatório: d65957b0-5c11-4f86-9789-61f590e0ccfd
Nome completo do pacote com falha: Microsoft.Windows.ShellExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy
ID do aplicativo relativo ao pacote com falha: App

Error: (01/16/2018 05:31:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: MicrosoftEdgeCP.exe, versão: 11.0.16299.15, carimbo de data/hora: 0x59cda7cd
Nome do módulo com falha: ntdll.dll, versão: 10.0.16299.64, carimbo de data/hora: 0x493793ea
Código de exceção: 0xcfffffff
Deslocamento da falha: 0x00000000000a0784
ID do processo com falha: 0xfc0
Hora de início do aplicativo com falha: 0x01d38f007ccb6552
Caminho do aplicativo com falha: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
Caminho do módulo com falha: C:\WINDOWS\SYSTEM32\ntdll.dll
ID do Relatório: 32f392fc-c77b-4ce1-b404-03d0809476b7
Nome completo do pacote com falha: Microsoft.MicrosoftEdge_41.16299.15.0_neutral__8wekyb3d8bbwe
ID do aplicativo relativo ao pacote com falha: ContentProcess

Error: (01/16/2018 05:31:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: MicrosoftEdgeCP.exe, versão: 11.0.16299.15, carimbo de data/hora: 0x59cda7cd
Nome do módulo com falha: win32u.dll, versão: 10.0.16299.15, carimbo de data/hora: 0x1900dcc9
Código de exceção: 0xcfffffff
Deslocamento da falha: 0x0000000000009164
ID do processo com falha: 0x102c
Hora de início do aplicativo com falha: 0x01d38effe0fca3fa
Caminho do aplicativo com falha: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
Caminho do módulo com falha: C:\WINDOWS\System32\win32u.dll
ID do Relatório: 963b39ae-6568-481b-ac26-57a452491faf
Nome completo do pacote com falha: Microsoft.MicrosoftEdge_41.16299.15.0_neutral__8wekyb3d8bbwe
ID do aplicativo relativo ao pacote com falha: ContentProcess

Error: (01/16/2018 05:18:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: Windows10UpgraderApp.exe, versão: 1.4.9200.22329, carimbo de data/hora: 0x5a1ca91b
Nome do módulo com falha: Windows10UpgraderApp.exe, versão: 1.4.9200.22329, carimbo de data/hora: 0x5a1ca91b
Código de exceção: 0xc0000005
Deslocamento da falha: 0x0001a098
ID do processo com falha: 0x1074
Hora de início do aplicativo com falha: 0x01d38efeb723e15c
Caminho do aplicativo com falha: C:\Windows10Upgrade\Windows10UpgraderApp.exe
Caminho do módulo com falha: C:\Windows10Upgrade\Windows10UpgraderApp.exe
ID do Relatório: ef8d8d1b-86dc-4fbe-bf06-be9928d7448d
Nome completo do pacote com falha:
ID do aplicativo relativo ao pacote com falha:

Error: (01/16/2018 04:46:47 PM) (Source: MSDTC Client 2) (EventID: 4104) (User: )
Description: Falha ao tentar obter o estado do nó do cluster: .Código de erro retornado: 0x8007085A

Error: (01/16/2018 04:45:50 PM) (Source: ESENT) (EventID: 455) (User: )
Description: mighost (3764,R,0) TILEREPOSITORYS-1-0-0: Erro -1023 (0xfffffc01) ao abrir o arquivo de log C:\Users\Default\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (01/16/2018 04:45:35 PM) (Source: MSDTC Client 2) (EventID: 4104) (User: )
Description: Falha ao tentar obter o estado do nó do cluster: .Código de erro retornado: 0x8007085A

Error: (01/16/2018 04:45:34 PM) (Source: MSDTC 2) (EventID: 4104) (User: )
Description: Falha ao tentar obter o estado do nó do cluster: .Código de erro retornado: 0x8007085A


Erros de Sistema:
=============
Error: (01/22/2018 04:42:35 PM) (Source: Disk) (EventID: 7) (User: )
Description: O dispositivo, \Device\Harddisk0\DR0, possui um setor defeituoso.

Error: (01/22/2018 04:42:32 PM) (Source: Disk) (EventID: 7) (User: )
Description: O dispositivo, \Device\Harddisk0\DR0, possui um setor defeituoso.

Error: (01/22/2018 03:56:49 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-520UTA6)
Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
e APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
ao usuário DESKTOP-520UTA6\Mário SID (S-1-5-21-1720934648-1002782208-2448832314-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes.

Error: (01/22/2018 02:54:39 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: O serviço Avira Service Host foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 10000 milissegundos: Reiniciar o serviço.

Error: (01/22/2018 02:54:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: O serviço Serviço Clique para Executar do Microsoft Office foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 0 milissegundos: Reiniciar o serviço.

Error: (01/22/2018 02:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço Intel(R) HD Graphics Control Panel Service foi encerrado inesperadamente. Isso aconteceu 1 vez(es).

Error: (01/22/2018 02:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço VIA Karaoke digital mixer Service foi encerrado inesperadamente. Isso aconteceu 1 vez(es).

Error: (01/22/2018 02:53:20 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-520UTA6)
Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
e APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
ao usuário DESKTOP-520UTA6\Mário SID (S-1-5-21-1720934648-1002782208-2448832314-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes.

Error: (01/22/2018 01:24:40 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-520UTA6)
Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
e APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
ao usuário DESKTOP-520UTA6\Mário SID (S-1-5-21-1720934648-1002782208-2448832314-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes.

Error: (01/21/2018 07:07:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-520UTA6)
Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
e APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
ao usuário DESKTOP-520UTA6\Mário SID (S-1-5-21-1720934648-1002782208-2448832314-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes.


==================== Informações da Memória ===========================

Processador: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
Percentagem de memória em uso: 68%
RAM física total: 3975.86 MB
RAM física disponível: 1256.77 MB
Virtual Total: 6535.86 MB
Virtual disponível: 3499.39 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:585.47 GB) (Free:543.06 GB) NTFS
Drive e: () (Fixed) (Total:345.48 GB) (Free:341.73 GB) NTFS

==================== MBR & Tabela de Partições ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 000777B1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=585.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=480 MB) - (Type=27)
Partition 4: (Not Active) - (Size=345.5 GB) - (Type=07 NTFS)

==================== Fim de Addition.txt ============================


Outra duvida, oq eu devo fazer aqui ?
Anexo do post

Anexos

Komm
Komm Cyber Highlander Registrado
12.8K Mensagens 2.7K Curtidas
#11 Por Komm
22/01/2018 - 17:29
Vou dar a real: O HD tem problemas e já foi bastante usado.

Tem 43 setores pendentes para correção. Mesmo número de setores que o SMART diz ser incorrigíveis.
Este parâmetro High Fly Writes em vermelho é apenas indicativo. Mais informações sobre ele aqui:
https://kb.acronis.com/content/9124

Miramos em uma coisa e apareceu outra maior.

[]s.
Legal mesmo é a cara do cachorro quando a bicicleta para! mostrando_dentes.png
Prongss
Prongss Membro Junior Registrado
34 Mensagens 16 Curtidas
#12 Por Prongss
22/01/2018 - 17:36
Alguma das ameaças encontradas pelo FRST e ZHP são realmente perigosas e dariam acesso a senhas ou dados pessoas ? Depois q reparei estou livre das pragas? Como posso identificar os problemas com o hd e tem algum deles que eu possa solucionar, formatando por exemplo ? devo levar o hd para algum técnico analisar ou deve esperar esse dar algum problema e comprar outro ?
Komm
Komm Cyber Highlander Registrado
12.8K Mensagens 2.7K Curtidas
#13 Por Komm
22/01/2018 - 17:47
Pelo log do ZHPCleaner, só tinha malwares leves. Nada a se preocupar.
Logs do AdwCleaner e da redundante JRT, limpos.

Sobre os logs da FRST, olhei bem por cima. Não encontrei problemas maiores.
O joram voltará aqui com um script para você executar e remover o que falta.

O que preocupa no teu micro é o HD, que está com os dias contados. Foi bom diagnosticá-lo antes dele morrer.
Assim tem tempo para copiar os dados importantes.

[]s.
Legal mesmo é a cara do cachorro quando a bicicleta para! mostrando_dentes.png
TmfeijoMMonroe
TmfeijoMMonr... Cyber Highlander Registrado
13.7K Mensagens 4.2K Curtidas
#14 Por TmfeijoMMonr...
22/01/2018 - 17:52
Boa tarde prezado autor !

Rode imediatamente a eset on line .
A mesma é muito eficiente. Podes acreditar. Pois se não vejamos:

https://www.hardware.com.br/comunidade/remover-mecanismo/1473705/

Tem mais malwares aí heim !

E o log do próprio malwarebytes ?

Abraços e poste o log
A ignorância é a pior inimiga do homem . Não tenho medo de nada; apenas da inveja . E o mundo cada vez melhor !!
Palavras sábias de um hiper profissional do judiciário; perito digital e em psicologia jurídica .
A sua inveja é a velocidade de meu sucesso .
Um coração medroso congela o trabalho . Um coração temerário incendeia qualquer serviço ; arrasando - o .
Prongss
Prongss Membro Junior Registrado
34 Mensagens 16 Curtidas
#15 Por Prongss
22/01/2018 - 19:39
ok muito obrigado pelo ajuda, ja salvei todos os arquivos importantes em pen drive.
Aqui estão os logs do Malwarebytes e realmente o Eset acabou encontrando mais algumas ameaças, mas são executáveis de programas que nem estão instalados, exceto o toolbar do ccleaner, mas segue o log tbm. Por precaução ameaças encontradas foram todas removidas.

"Malwarebytes"

Malwarebytes
www.malwarebytes.com

-Detalhes de registro-
Data da análise: 22/01/18
Hora da análise: 17:58
Arquivo de registro: a7a8208e-ffae-11e7-9ba9-eca86bba5a23.json
Administrador: Sim

-Informação do software-
Versão: 3.3.1.2183
Versão de componentes: 1.0.262
Versão do pacote de definições: 1.0.3755
Licença: Versão de Avaliação

-Informação do sistema-
Sistema operacional: Windows 10 (Build 16299.192)
CPU: x64
Sistema de arquivos: NTFS
Usuário: DESKTOP-520UTA6\M\u00c3\u00a1rio

-Resumo da análise-
Tipo de análise: Análise de Ameaças
Resultado: Concluído
Objetos verificados: 279056
Ameaças detectadas: 0
(Nenhum item malicioso detectado)
Ameaças em quarentena: 0
(Nenhum item malicioso detectado)
Tempo decorrido: 2 min, 14 seg

-Opções da análise-
Memória: Habilitado
Inicialização: Habilitado
Sistema de arquivos: Habilitado
Arquivos compactados: Habilitado
Rootkits: Desabilitado
Heurística: Habilitado
PUP: Detectar
PUM: Detectar

-Detalhes da análise-
Processo: 0
(Nenhum item malicioso detectado)

Módulo: 0
(Nenhum item malicioso detectado)

Chave de registro: 0
(Nenhum item malicioso detectado)

Valor de registro: 0
(Nenhum item malicioso detectado)

Dados de registro: 0
(Nenhum item malicioso detectado)

Fluxo de dados: 0
(Nenhum item malicioso detectado)

Pasta: 0
(Nenhum item malicioso detectado)

Arquivo: 0
(Nenhum item malicioso detectado)

Setor físico: 0
(Nenhum item malicioso detectado)


(end)


"Eset"

C:\Users\Mário\Downloads\ccsetup539.exe Win32/Bundled.Toolbar.Google.D Aplicativo potencialmente insegura limpo por exclusão
E:\Yago\COISAS\Arquivos\Programas\aTube_Catcher_ATU3_9110.exe uma variante de Win32/Bundled.Toolbar.Ask.N Aplicativo potencialmente insegura limpo por exclusão
E:\Yago\COISAS\Arquivos\Programas\ccsetup530.exe Win32/Bundled.Toolbar.Google.D Aplicativo potencialmente insegura limpo por exclusão
E:\Yago\COISAS\outras coisas\Downloads\Office\AT O2016 By Baixar Seguro.rar uma variante de MSIL/HackTool.IdleKMS.E Aplicativo potencialmente insegura excluído

© 1999-2025 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal