Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus spam ad..


  • This topic is locked This topic is locked
3 replies to this topic

#1 Matszg

Matszg

  • Members
  • 2 posts
  • OFFLINE
  •  

Posted 19 July 2018 - 03:08 PM

I got an virus here, he dont let me download any malware remover, or even tipe malware on browser and spam ad random on the browser
This is the log on hijackthis
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 17:05:04, on 19/07/2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Users\Matheus Zanutto\AppData\Local\Microsoft\OneDrive\OneDrive.exe
D:\Steam\Steam.exe
C:\Users\Matheus Zanutto\AppData\Local\Discord\app-0.0.301\Discord.exe
C:\Users\Matheus Zanutto\AppData\Local\Discord\app-0.0.301\Discord.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Users\Matheus Zanutto\AppData\Local\Discord\app-0.0.301\Discord.exe
C:\WINDOWS\SysWOW64\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Users\Matheus Zanutto\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe
C:\WINDOWS\SysWOW64\svchost.exe
D:\Downloads\HijackThis.exe
C:\WINDOWS\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Matheus Zanutto\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "D:\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Discord] C:\Users\Matheus Zanutto\AppData\Local\Discord\app-0.0.301\Discord.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVIÇO DE REDE')
O4 - HKUS\S-1-5-20\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'SERVIÇO DE REDE')
O4 - Startup: Monitorar alertas de tinta - HP Deskjet 1510 series.lnk = ?
O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: KMS-R@1n - Unknown owner - C:\Windows\KMS-R@1n.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Origin Client Service - Electronic Arts - D:\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Origin\OriginWebHelperService.exe
O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 13 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\xbgmsvc.exe (file missing)

--
End of file - 10153 bytes
Thanks for the help

BC AdBot (Login to Remove)

 


#2 Matszg

Matszg
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  

Posted 19 July 2018 - 04:05 PM

This is the FRST.log
Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 15.07.2018
Executado por Matheus Zanutto (administrador) em DESKTOP-Q3D5SVE (19-07-2018 17:53:52)
Executando a partir de D:\Downloads
Perfis Carregados: Matheus Zanutto (Perfis Disponíveis: Matheus Zanutto)
Platform: Windows 10 Pro Versão 1803 17134.165 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: FF)
Modo da Inicialização: Safe Mode (with Networking)
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-07-19] (AVAST Software)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596664 2018-01-15] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\Run: [Steam] => D:\Steam\steam.exe [3201312 2018-06-08] (Valve Corporation)
HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\Run: [Discord] => C:\Users\Matheus Zanutto\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\RunOnce: [Application Restart #0] => C:\Windows\System32\Taskmgr.exe [1326952 2018-04-11] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk [2018-04-09]
ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.)
Startup: C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitorar alertas de tinta - HP Deskjet 1510 series.lnk [2018-07-19]
ShortcutTarget: Monitorar alertas de tinta - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\..\Interfaces\{38306256-5543-4ed7-aba6-fa6614866829}: [DhcpNameServer] 208.67.222.222 208.67.220.220

Internet Explorer:
==================
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-05-11] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-05-11] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 214l4ozi.default
FF ProfilePath: C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default [2018-07-19]
FF Homepage: Mozilla\Firefox\Profiles\214l4ozi.default -> about:home
FF Extension: (MyJDownloader Browser Extension) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\jid1-OY8Xu5BsKZQa6A@jetpack.xpi [2018-07-17]
FF Extension: (uBlock Origin) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\uBlock0@raymondhill.net.xpi [2018-07-18]
FF Extension: (Avast Online Security) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\wrc@avast.com.xpi [2018-07-19]
FF Extension: (openwpdf) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\{2582ab30-4fca-475f-88d0-c1a9b9ed978f}.xpi [2018-04-08]
FF Extension: (Video DownloadHelper) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-07-12]
FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2018-07-12] [Legacy] [não assinado]
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-05-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-05-11] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-19] (Google Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default [2018-07-19]
CHR Extension: (Apresentações) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-19]
CHR Extension: (Documentos) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-19]
CHR Extension: (Google Drive) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-19]
CHR Extension: (YouTube) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-19]
CHR Extension: (Planilhas) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-19]
CHR Extension: (Documentos Google off-line) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-19]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-19]
CHR Extension: (Gmail) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-19]
CHR Extension: (Chrome Media Router) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-19]

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7780400 2018-07-19] (AVAST Software)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-07-19] (AVAST Software)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Arquivo não assinado]
S2 Intel® PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [505856 2018-01-31] (Intel Corporation) [Arquivo não assinado]
S2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2018-04-08] () [Arquivo não assinado]
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2158912 2018-04-23] (Electronic Arts)
S2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [3028808 2018-04-23] (Electronic Arts)
S2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2017-07-19] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
S3 VSStandardCollectorService150; D:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [145512 2018-01-23] (Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
S2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (Apple Inc.)
S1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [197160 2018-07-19] (AVAST Software)
S1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [229392 2018-07-19] (AVAST Software)
S0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [201328 2018-07-19] (AVAST Software)
S0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [346664 2018-07-19] (AVAST Software)
S0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [59592 2018-07-19] (AVAST Software)
S3 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15360 2018-07-19] (AVAST Software)
S1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [239680 2018-07-19] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46976 2018-07-19] (AVAST Software)
S2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [159640 2018-07-19] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111872 2018-07-19] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [85968 2018-07-19] (AVAST Software)
S1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1027728 2018-07-19] (AVAST Software)
S1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [463080 2018-07-19] (AVAST Software)
S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [211160 2018-07-19] (AVAST Software)
S0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [381584 2018-07-19] (AVAST Software)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30352 2018-04-08] (Disc Soft Ltd)
R3 e1cexpress; C:\WINDOWS\system32\DRIVERS\e1c65x64.sys [472016 2016-07-18] (Intel Corporation)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
S3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_desktop_ref4wu.inf_amd64_0109a19b5125cb43\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc)
S2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [45752 2017-07-19] (Razer, Inc.)
S2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [139704 2017-08-19] (Razer, Inc.)
S3 smbdirect; C:\WINDOWS\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2018-07-19 17:53 - 2018-07-19 17:53 - 000000000 ____D C:\FRST
2018-07-19 16:45 - 2018-07-19 16:45 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-07-19 16:45 - 2018-07-19 16:45 - 000002334 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-07-19 16:44 - 2018-07-19 16:49 - 000003588 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-07-19 16:44 - 2018-07-19 16:49 - 000003464 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-07-19 16:44 - 2018-07-19 16:45 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\Google
2018-07-19 16:44 - 2018-07-19 16:45 - 000000000 ____D C:\Program Files (x86)\Google
2018-07-19 16:43 - 2018-07-19 16:57 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\AVAST Software
2018-07-19 16:43 - 2018-07-19 16:43 - 000001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2018-07-19 16:43 - 2018-07-19 16:43 - 000001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2018-07-19 16:43 - 2018-07-19 16:43 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\AVAST Software
2018-07-19 16:37 - 2018-07-19 17:53 - 000646276 _____ C:\WINDOWS\ntbtlog.txt
2018-07-19 16:37 - 2018-07-19 17:52 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2018-07-19 16:33 - 2018-07-19 16:33 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software
2018-07-19 16:32 - 2018-07-19 16:32 - 001027728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000463080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000381584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000378072 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-07-19 16:32 - 2018-07-19 16:32 - 000346664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000239680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000229392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000211160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000201328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000197160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000159640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000111872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000085968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000059592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000046976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000015360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000003990 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2018-07-19 16:32 - 2018-07-19 16:32 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2018-07-19 16:30 - 2018-07-19 16:32 - 000000000 ____D C:\Users\Todos os Usuários\AVAST Software
2018-07-19 16:30 - 2018-07-19 16:32 - 000000000 ____D C:\ProgramData\AVAST Software
2018-07-19 16:30 - 2018-07-19 16:30 - 000000000 ____D C:\Program Files\AVAST Software
2018-07-19 14:18 - 2018-07-19 14:18 - 000003908 _____ C:\WINDOWS\System32\Tasks\{974F87F5-E009-F0AD-8F98-7D4B120EBEB8}
2018-07-19 14:18 - 2018-07-19 14:18 - 000003822 _____ C:\WINDOWS\System32\Tasks\{B8A3717B-7F7A-4623-C344-C5DC638D4455}
2018-07-19 14:18 - 2018-07-19 14:18 - 000003634 _____ C:\WINDOWS\System32\Tasks\{F5007D8A-A700-02EA-1ECF-E738E9566150}
2018-07-19 14:18 - 2018-07-19 14:18 - 000000002 _____ C:\Users\Matheus Zanutto\AppData\Local\imw.ini
2018-07-10 15:59 - 2018-07-06 11:20 - 001610648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-07-10 15:59 - 2018-07-06 11:20 - 000689560 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-07-10 15:59 - 2018-07-06 11:15 - 002266520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2018-07-10 15:59 - 2018-07-06 10:56 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-07-10 15:59 - 2018-07-06 10:51 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-07-10 15:59 - 2018-07-06 09:12 - 001539000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2018-07-10 15:59 - 2018-07-06 08:26 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-07-10 15:59 - 2018-07-06 08:25 - 023863296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-07-10 15:59 - 2018-07-06 04:31 - 000462752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-07-10 15:59 - 2018-07-06 04:25 - 009147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-07-10 15:59 - 2018-07-06 04:10 - 025845760 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-07-10 15:59 - 2018-07-06 04:07 - 022006272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-07-10 15:59 - 2018-07-06 04:04 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-07-10 15:59 - 2018-07-06 04:03 - 004371456 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-07-10 15:59 - 2018-07-06 04:02 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2018-07-10 15:59 - 2018-07-06 04:01 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2018-07-10 15:59 - 2018-07-06 04:00 - 019403264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-07-10 15:59 - 2018-07-06 03:58 - 004867584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-07-10 15:59 - 2018-07-06 03:57 - 007579648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-07-10 15:59 - 2018-07-06 03:57 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-07-10 15:59 - 2018-07-06 03:56 - 001817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-07-10 15:59 - 2018-07-06 03:55 - 003440128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-07-10 15:59 - 2018-06-15 14:49 - 021388856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-07-10 15:59 - 2018-06-15 14:33 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-07-10 15:59 - 2018-06-15 12:25 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-07-10 15:59 - 2018-06-15 12:07 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-07-10 15:59 - 2018-06-15 02:21 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-07-10 15:59 - 2018-06-15 02:12 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-07-10 15:59 - 2018-06-15 02:11 - 006817872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-07-10 15:59 - 2018-06-15 02:09 - 007436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-07-10 15:59 - 2018-06-15 02:09 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 004403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 001288840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-07-10 15:59 - 2018-06-15 02:07 - 001611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-07-10 15:59 - 2018-06-15 02:07 - 001145696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2018-07-10 15:59 - 2018-06-15 02:04 - 002331576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 006572000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 006528600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 006043600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 004788504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 001710240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 001144120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 001020160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-07-10 15:59 - 2018-06-15 01:46 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-07-10 15:59 - 2018-06-15 01:44 - 005746688 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2018-07-10 15:59 - 2018-06-15 01:42 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-07-10 15:59 - 2018-06-15 01:42 - 002367488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-07-10 15:59 - 2018-06-15 01:41 - 004561920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 002868640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-07-10 15:58 - 2018-07-06 11:20 - 000792472 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000451992 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000309664 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000144792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-07-10 15:58 - 2018-07-06 11:20 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-07-10 15:58 - 2018-07-06 11:17 - 003932672 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-07-10 15:58 - 2018-07-06 11:14 - 000541592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000672768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-07-10 15:58 - 2018-07-06 10:52 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-07-10 15:58 - 2018-07-06 10:52 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-07-10 15:58 - 2018-07-06 10:51 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-07-10 15:58 - 2018-07-06 10:51 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-07-10 15:58 - 2018-07-06 10:51 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-07-10 15:58 - 2018-07-06 10:51 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-07-10 15:58 - 2018-07-06 10:50 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-07-10 15:58 - 2018-07-06 10:49 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-07-10 15:58 - 2018-07-06 09:06 - 003611368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-07-10 15:58 - 2018-07-06 08:54 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-07-10 15:58 - 2018-07-06 08:54 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-07-10 15:58 - 2018-07-06 08:53 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-07-10 15:58 - 2018-07-06 08:53 - 000565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2018-07-10 15:58 - 2018-07-06 08:53 - 000347136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-07-10 15:58 - 2018-07-06 08:52 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-07-10 15:58 - 2018-07-06 08:52 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-07-10 15:58 - 2018-07-06 08:52 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-07-10 15:58 - 2018-07-06 08:51 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-07-10 15:58 - 2018-07-06 08:51 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-07-10 15:58 - 2018-07-06 08:01 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-07-10 15:58 - 2018-07-06 04:32 - 000480672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-07-10 15:58 - 2018-07-06 04:31 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-07-10 15:58 - 2018-07-06 04:29 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-07-10 15:58 - 2018-07-06 04:29 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-07-10 15:58 - 2018-07-06 04:27 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-07-10 15:58 - 2018-07-06 04:27 - 001063320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-07-10 15:58 - 2018-07-06 04:27 - 001012632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-07-10 15:58 - 2018-07-06 04:27 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-07-10 15:58 - 2018-07-06 04:27 - 000567176 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-07-10 15:58 - 2018-07-06 04:27 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-07-10 15:58 - 2018-07-06 04:27 - 000057440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2018-07-10 15:58 - 2018-07-06 04:26 - 002712992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-07-10 15:58 - 2018-07-06 04:26 - 001148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-07-10 15:58 - 2018-07-06 04:26 - 000930720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-07-10 15:58 - 2018-07-06 04:26 - 000766608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2018-07-10 15:58 - 2018-07-06 04:26 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-07-10 15:58 - 2018-07-06 04:25 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 002571728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 002420632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-07-10 15:58 - 2018-07-06 04:25 - 001945784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 001026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-07-10 15:58 - 2018-07-06 04:25 - 001018616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000885856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000483048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000267680 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2018-07-10 15:58 - 2018-07-06 04:24 - 000380824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-07-10 15:58 - 2018-07-06 04:16 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 001981896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 001175568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 000988640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-07-10 15:58 - 2018-07-06 04:14 - 000573904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2018-07-10 15:58 - 2018-07-06 04:13 - 001620872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-07-10 15:58 - 2018-07-06 04:01 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2018-07-10 15:58 - 2018-07-06 04:01 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2018-07-10 15:58 - 2018-07-06 04:01 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsTelemetry.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 001153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 001931776 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-07-10 15:58 - 2018-07-06 03:58 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000676864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 003015680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-07-10 15:58 - 2018-07-06 03:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2018-07-10 15:58 - 2018-07-06 03:52 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-07-10 15:58 - 2018-07-06 02:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-07-10 15:58 - 2018-06-29 01:16 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-10 15:58 - 2018-06-15 14:55 - 000542888 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2018-07-10 15:58 - 2018-06-15 14:53 - 000348256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-07-10 15:58 - 2018-06-15 14:53 - 000094104 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-07-10 15:58 - 2018-06-15 14:50 - 001376576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-07-10 15:58 - 2018-06-15 14:48 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-07-10 15:58 - 2018-06-15 14:48 - 000338352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2018-07-10 15:58 - 2018-06-15 14:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-07-10 15:58 - 2018-06-15 14:34 - 008623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-07-10 15:58 - 2018-06-15 14:34 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2018-07-10 15:58 - 2018-06-15 14:34 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2018-07-10 15:58 - 2018-06-15 14:33 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2018-07-10 15:58 - 2018-06-15 14:33 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
2018-07-10 15:58 - 2018-06-15 14:33 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-10 15:58 - 2018-06-15 14:32 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
2018-07-10 15:58 - 2018-06-15 14:32 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
2018-07-10 15:58 - 2018-06-15 14:32 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2018-07-10 15:58 - 2018-06-15 14:32 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2018-07-10 15:58 - 2018-06-15 14:31 - 002193920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2018-07-10 15:58 - 2018-06-15 14:31 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-07-10 15:58 - 2018-06-15 14:31 - 000907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\autofmt.exe
2018-07-10 15:58 - 2018-06-15 14:31 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 001308672 _____ C:\WINDOWS\system32\FaceProcessor.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 001254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 001186816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
2018-07-10 15:58 - 2018-06-15 14:29 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-07-10 15:58 - 2018-06-15 14:29 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
2018-07-10 15:58 - 2018-06-15 14:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-07-10 15:58 - 2018-06-15 14:29 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-07-10 15:58 - 2018-06-15 14:29 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2018-07-10 15:58 - 2018-06-15 14:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSoftwareInstallationClient.dll
2018-07-10 15:58 - 2018-06-15 14:28 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2018-07-10 15:58 - 2018-06-15 14:28 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2018-07-10 15:58 - 2018-06-15 14:03 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe
2018-07-10 15:58 - 2018-06-15 14:00 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
2018-07-10 15:58 - 2018-06-15 12:22 - 001026896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-07-10 15:58 - 2018-06-15 12:16 - 002206528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-07-10 15:58 - 2018-06-15 12:06 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-07-10 15:58 - 2018-06-15 12:06 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2018-07-10 15:58 - 2018-06-15 12:04 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
2018-07-10 15:58 - 2018-06-15 12:04 - 000373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2018-07-10 15:58 - 2018-06-15 12:03 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autofmt.exe
2018-07-10 15:58 - 2018-06-15 12:03 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-07-10 15:58 - 2018-06-15 12:02 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-07-10 15:58 - 2018-06-15 12:01 - 002015744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-07-10 15:58 - 2018-06-15 12:01 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2018-07-10 15:58 - 2018-06-15 10:23 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-07-10 15:58 - 2018-06-15 04:11 - 000611232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-07-10 15:58 - 2018-06-15 04:10 - 000048544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-07-10 15:58 - 2018-06-15 04:03 - 000083360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-07-10 15:58 - 2018-06-15 02:21 - 000761440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-07-10 15:58 - 2018-06-15 02:19 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-07-10 15:58 - 2018-06-15 02:19 - 000116632 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2018-07-10 15:58 - 2018-06-15 02:19 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-07-10 15:58 - 2018-06-15 02:18 - 000228768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-07-10 15:58 - 2018-06-15 02:16 - 000562080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-07-10 15:58 - 2018-06-15 02:16 - 000433560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-07-10 15:58 - 2018-06-15 02:15 - 002563960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:15 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-07-10 15:58 - 2018-06-15 02:13 - 000510904 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2018-07-10 15:58 - 2018-06-15 02:13 - 000324000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000661152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000491304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 001097640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-07-10 15:58 - 2018-06-15 02:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-07-10 15:58 - 2018-06-15 02:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2018-07-10 15:58 - 2018-06-15 02:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-07-10 15:58 - 2018-06-15 02:08 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-07-10 15:58 - 2018-06-15 02:08 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-07-10 15:58 - 2018-06-15 02:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-07-10 15:58 - 2018-06-15 02:08 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-07-10 15:58 - 2018-06-15 02:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-07-10 15:58 - 2018-06-15 02:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-07-10 15:58 - 2018-06-15 02:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2018-07-10 15:58 - 2018-06-15 02:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-07-10 15:58 - 2018-06-15 02:05 - 000444240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001380192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2018-07-10 15:58 - 2018-06-15 02:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-07-10 15:58 - 2018-06-15 01:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-07-10 15:58 - 2018-06-15 01:48 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-07-10 15:58 - 2018-06-15 01:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-07-10 15:58 - 2018-06-15 01:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2018-07-10 15:58 - 2018-06-15 01:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2018-07-10 15:58 - 2018-06-15 01:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 004529664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2018-07-10 15:58 - 2018-06-15 01:46 - 004333568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 002548736 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2018-07-10 15:58 - 2018-06-15 01:45 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2018-07-10 15:58 - 2018-06-15 01:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 001632256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2018-07-10 15:58 - 2018-06-15 01:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-07-10 15:58 - 2018-06-15 01:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2018-07-10 15:58 - 2018-06-15 01:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-07-10 15:58 - 2018-06-15 01:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-07-10 15:58 - 2018-06-15 01:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2018-07-10 15:58 - 2018-06-15 01:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2018-07-10 15:58 - 2018-06-15 01:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 002903040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-07-10 15:58 - 2018-06-15 01:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-07-10 15:58 - 2018-06-15 01:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-07-10 15:58 - 2018-06-15 01:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
2018-07-10 15:58 - 2018-06-01 02:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
2018-07-10 15:58 - 2018-05-20 08:53 - 000792984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-07-10 15:58 - 2018-05-20 08:52 - 000413080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-06-27 14:17 - 2018-06-27 14:17 - 000002454 _____ C:\Users\Matheus Zanutto\Desktop\CurrencyCop.lnk
2018-06-27 14:17 - 2018-06-27 14:17 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nijiko Yonskai
2018-06-26 14:09 - 2018-06-26 14:09 - 000000202 _____ C:\Users\Matheus Zanutto\Desktop\Realm Royale.url
2018-06-22 16:26 - 2018-06-22 16:26 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\LocalLow\Temp
2018-06-20 10:29 - 2018-07-19 17:07 - 000000000 ____D C:\Users\Todos os Usuários\Packages
2018-06-20 10:29 - 2018-07-19 17:07 - 000000000 ____D C:\ProgramData\Packages

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2018-07-19 17:52 - 2018-04-11 18:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-19 17:51 - 2018-05-22 04:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-19 17:41 - 2018-04-08 13:27 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\LocalLow\Mozilla
2018-07-19 17:33 - 2018-05-22 04:04 - 001737602 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-07-19 17:33 - 2018-04-12 13:37 - 000750582 _____ C:\WINDOWS\system32\prfh0416.dat
2018-07-19 17:33 - 2018-04-12 13:37 - 000147916 _____ C:\WINDOWS\system32\prfc0416.dat
2018-07-19 17:33 - 2018-04-11 20:36 - 000000000 ____D C:\WINDOWS\INF
2018-07-19 17:27 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-19 17:26 - 2018-05-22 05:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-07-19 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft
2018-07-19 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-19 17:26 - 2018-04-08 13:58 - 000000000 ____D C:\Users\Todos os Usuários\NVIDIA
2018-07-19 17:26 - 2018-04-08 13:58 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-19 17:20 - 2018-04-11 20:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-07-19 17:07 - 2018-04-11 20:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-19 16:43 - 2018-04-08 13:20 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\VirtualStore
2018-07-19 16:42 - 2018-05-22 03:56 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-07-19 16:38 - 2018-05-22 04:22 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\ElevatedDiagnostics
2018-07-19 16:32 - 2018-04-11 20:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-07-19 16:31 - 2018-04-08 13:39 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\PlaceholderTileLogoFolder
2018-07-19 16:31 - 2018-04-08 13:20 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\Packages
2018-07-19 16:14 - 2018-04-08 13:27 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-07-19 16:14 - 2018-04-08 13:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-07-17 16:42 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-07-16 20:40 - 2018-04-08 15:23 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-07-16 15:08 - 2018-04-08 15:01 - 000000000 ____D C:\Program Files (x86)\Corel
2018-07-13 18:22 - 2018-05-22 04:01 - 000003398 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1958513911-1346653992-1749791109-1001
2018-07-13 18:22 - 2018-05-22 03:57 - 000002403 _____ C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-07-13 18:22 - 2018-04-08 13:22 - 000000000 ___RD C:\Users\Matheus Zanutto\OneDrive
2018-07-13 16:25 - 2018-06-05 19:03 - 000002703 _____ C:\Users\Matheus Zanutto\Desktop\poe things.txt
2018-07-12 05:29 - 2018-06-14 22:10 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\D3DSCache
2018-07-12 05:28 - 2018-04-08 13:27 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-07-11 17:40 - 2018-05-22 03:56 - 000330448 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-07-11 17:40 - 2018-04-08 13:20 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-11 17:40 - 2018-04-08 13:20 - 000000000 ___RD C:\Users\Matheus Zanutto\3D Objects
2018-07-11 17:39 - 2018-05-22 03:57 - 000000000 ____D C:\Users\Matheus Zanutto
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-07-10 16:02 - 2018-04-08 15:29 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-07-10 16:01 - 2018-04-08 15:29 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-06-28 22:13 - 2018-04-11 20:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-06-28 22:13 - 2018-04-11 20:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-27 14:18 - 2018-04-09 10:11 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\currency-cop
2018-06-26 14:09 - 2018-04-08 15:15 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-26 13:17 - 2018-04-08 15:30 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-24 04:03 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports

==================== Arquivos na raiz de alguns diretórios =======

2018-04-11 20:34 - 2018-04-11 20:34 - 000059904 ____N (Microsoft Corporation) C:\Program Files (x86)\oijYoXoQIUk.exe
2018-04-11 20:34 - 2018-04-11 20:34 - 000059904 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\hCEC.exe
2018-04-11 20:34 - 2018-04-11 20:34 - 000178688 ____N (Microsoft Corporation) C:\Users\Matheus Zanutto\AppData\Local\fOsZDucgnaEUI.exe
2018-07-19 14:18 - 2018-07-19 14:18 - 000000002 _____ () C:\Users\Matheus Zanutto\AppData\Local\imw.ini

Alguns arquivos em TEMP:
====================
2018-07-12 08:26 - 2018-07-12 08:26 - 000080114 _____ () C:\Users\Matheus Zanutto\AppData\Local\Temp\JNativeHook-3772166911178909660.dll
2018-07-18 00:03 - 2018-07-18 00:03 - 000040448 ____N () C:\Users\Matheus Zanutto\AppData\Local\Temp\proxy_vole1362597998321394276.dll
2018-07-18 00:03 - 2018-07-18 00:03 - 000040448 ____N () C:\Users\Matheus Zanutto\AppData\Local\Temp\proxy_vole4578809522435123710.dll
2018-07-18 00:03 - 2018-07-18 00:03 - 000040448 ____N () C:\Users\Matheus Zanutto\AppData\Local\Temp\proxy_vole6007850103480906827.dll

==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

LastRegBack: 2018-05-22 03:56

==================== Fim de FRST.txt ============================
And this is the additional.log
Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 15.07.2018
Executado por Matheus Zanutto (19-07-2018 17:54:20)
Executando a partir de D:\Downloads
Windows 10 Pro Versão 1803 17134.165 (X64) (2018-05-22 07:01:09)
Modo da Inicialização: Safe Mode (with Networking)
==========================================================


==================== Contas: =============================

Administrador (S-1-5-21-1958513911-1346653992-1749791109-500 - Administrator - Disabled)
Convidado (S-1-5-21-1958513911-1346653992-1749791109-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1958513911-1346653992-1749791109-503 - Limited - Disabled)
Matheus Zanutto (S-1-5-21-1958513911-1346653992-1749791109-1001 - Administrator - Enabled) => C:\Users\Matheus Zanutto
WDAGUtilityAccount (S-1-5-21-1958513911-1346653992-1749791109-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 29.0.0.112 - Adobe Systems Incorporated)
Application Verifier x64 External Package (HKLM\...\{62CB44B2-8007-DBB2-1CBA-5CB7309EB3C3}) (Version: 10.1.17134.12 - Microsoft) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.5.2342 - AVAST Software)
Citra (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\{0e4f00d2-d910-46cc-aed9-3d8453954064}) (Version: 1.0.0 - Citra Team)
Corel Graphics - Windows Shell Extension (HKLM\...\_{3CAAE169-6001-48ED-B2C6-5B6F511552FD}) (Version: 18.0.0.448 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM\...\{3CAAE169-6001-48ED-B2C6-5B6F511552FD}) (Version: 18.0.448 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit Keys (HKLM\...\{C8730B1A-133D-4546-8E21-9EC186341F20}) (Version: 18.0.448 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - BR (x64) (HKLM\...\{67D57366-EFCC-46DA-BB1F-BBE89B377177}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Capture (x64) (HKLM\...\{1253ED86-69FD-4A7B-BDF2-96A522583A88}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Common (x64) (HKLM\...\{72922AB6-F920-4C98-985D-EC90CE0918D4}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Connect (x64) (HKLM\...\{9782A612-03A7-488F-A598-33558163D8F8}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - CS (x64) (HKLM\...\{300DB480-7301-436A-A312-B695B2BC6D71}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - CT (x64) (HKLM\...\{43C4A17D-93D9-41C6-8ACA-370EA390ED2A}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Custom Data (x64) (HKLM\...\{02C85FBD-87D3-4352-BF2E-AFE897CD5559}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - CZ (x64) (HKLM\...\{A67AEE14-0435-4B8C-A367-F5EDE6CAF9F6}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - DE (x64) (HKLM\...\{4AA43BE3-D21B-44D7-B9CD-86692DEF3706}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Draw (x64) (HKLM\...\{A66E09BB-9892-421D-9EB9-311D12AA5244}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - EN (x64) (HKLM\...\{A0845CAD-ED13-46A4-A050-5ACE4631FDEC}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - ES (x64) (HKLM\...\{B1452C41-DC90-4B58-8320-ABB515E87FFB}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Filters (x64) (HKLM\...\{6E6D1438-33CC-413B-BC96-3497B1271CDD}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Font Manager (x64) (HKLM\...\{5FB5FF89-0938-49D9-850B-53B78B84A7E4}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - FR (x64) (HKLM\...\{0A182180-3BAF-4B94-BFD0-CF082CC5FF0D}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - IPM (x64) (HKLM\...\{A040C72A-0ADC-4FB9-9DB4-19B18F6053F1}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - IPM Content (x64) (HKLM\...\{FB081BA0-08D2-4C8C-9E55-788A90430BE3}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - IT (x64) (HKLM\...\{8285FEBA-D373-493F-BC78-934F84A0A298}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - JP (x64) (HKLM\...\{F5A1D3E4-416E-4723-AD35-86A372B99174}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - NL (x64) (HKLM\...\{A7922CC8-0EBD-497B-B381-5B3992905327}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - PHOTO-PAINT (x64) (HKLM\...\{04D8C47E-C0FE-4CA5-8878-91ECD9552109}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - PL (x64) (HKLM\...\{6F03D92C-48DB-4182-8A51-BEF8FE64B72C}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Redist (x64) (HKLM\...\{50D1BD2D-6D8C-45A8-9DB5-CDAB7227DB36}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - RU (x64) (HKLM\...\{B83D220A-33AB-4AF5-963A-887BD971270E}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Setup Files (x64) (HKLM\...\{4B3FC55D-E999-4BEC-AF29-1091E574961F}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - VBA (x64) (HKLM\...\{48DD8181-A983-447B-9660-A55A935CA751}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - VideoBrowser (x64) (HKLM\...\{81EBD8D4-9142-4D33-BF34-D99EFC1180F5}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Workspaces (x64) (HKLM\...\{1D4B870D-A5A8-4B88-9520-ED8EFD545AA1}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Writing Tools (x64) (HKLM\...\{23A2ABD8-8231-48AD-AD71-FF0566A7DD8F}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 (64-Bit) (HKLM\...\_{4B3FC55D-E999-4BEC-AF29-1091E574961F}) (Version: 18.0.0.448 - Corel Corporation)
CorelDRAW Graphics Suite X8 (HKLM\...\{ECFAF1D6-342D-4AE2-B6BF-82B22F9FE8DE}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 -TR (x64) (HKLM\...\{ACC8C1B0-E560-4B42-AA52-9CAD14883B29}) (Version: 18.0 - Corel Corporation) Hidden
CurrencyCop 2.0.0-beta.12 (only current user) (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\ad9b865c-58dc-5b28-b27d-6ee8d988422e) (Version: 2.0.0-beta.12 - Nijiko Yonskai)
Dark Souls 3 (HKLM-x32\...\Dark Souls 3_is1) (Version: - )
Dauntless (HKLM\...\{03AFDFA7-7A23-41B1-AAC2-3898591127D3}) (Version: 1.00.0000 - Phoenix Labs)
DiagnosticsHub_CollectionService (HKLM\...\{0CB7B447-4937-4945-B8C0-807A77B830D5}) (Version: 15.7.27520 - Microsoft Corporation) Hidden
Discord (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\Discord) (Version: 0.0.301 - Discord Inc.)
Estudo de aprimoramento de produto para HP Deskjet 1510 series (HKLM\...\{4BAE2611-A06F-4204-AFEC-EF04BF48013E}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\_{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation)
Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation) Hidden
GIGABYTE OC_GURU II (HKLM-x32\...\{5588D686-D23B-4C9D-BDFA-2A7875CD3722}) (Version: 1.56.0000 - GIGABYTE Technology Co.,Ltd.) Hidden
GIGABYTE OC_GURU II (HKLM-x32\...\InstallShield_{5588D686-D23B-4C9D-BDFA-2A7875CD3722}) (Version: 1.56.0000 - GIGABYTE Technology Co.,Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
HP Deskjet 1510 series Ajuda (HKLM-x32\...\{6DFDA448-D4A1-49DB-9217-1501D24861F5}) (Version: 30.0.0 - Hewlett Packard)
HP Deskjet 1510 series Software básico do dispositivo (HKLM\...\{06FD25AF-70F0-4CA9-88EA-490799567F11}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
icecap_collection_neutral (HKLM-x32\...\{12C1EC05-F936-4A80-821E-7AAC64C4E6FF}) (Version: 15.6.27413 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{C8E22DF4-5498-4B61-93CF-3081BE95A1BA}) (Version: 15.6.27413 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{FA83FF72-A39F-487F-9FD5-126C85600DCA}) (Version: 15.6.27406 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{DDDDF8F8-C8B3-4D0E-9679-B96EA592AD75}) (Version: 15.6.27406 - Microsoft Corporation) Hidden
Intel® C++ Redistributables for Windows* on Intel® 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel® Network Connections 23.1.100.0 (HKLM\...\PROSetDX) (Version: 23.1.100.0 - Intel)
IPM_Common_x64 (HKLM\...\{B8C05FFE-C36F-4F17-AD20-739E4BC65AC9}) (Version: 2.9.389 - Your Company Name) Hidden
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kits Configuration Installer (HKLM-x32\...\{6F502640-B753-C101-FFA5-B38C3FA5B29A}) (Version: 10.1.17134.12 - Microsoft) Hidden
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Microsoft OneDrive (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation)
Microsoft System CLR Types para SQL Server 2017 (HKLM\...\{7F1387A5-855C-43FB-8214-F544009A2026}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft System CLR Types para SQL Server 2017 (HKLM-x32\...\{009580F9-5D92-4824-A7B5-33DA6593703F}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26405 (HKLM-x32\...\{5b295ba9-ef89-4aeb-8acc-b61adb0b9b5f}) (Version: 14.14.26405.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26405 (HKLM-x32\...\{ec9c2282-a836-48a6-9e41-c2f0bf8d678b}) (Version: 14.14.26405.0 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 1.16.1243.427 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\...\{dd8b09df-3ef8-49f1-bd1a-65278435860b}) (Version: 14.0.23217 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 61.0.1 (x64 pt-BR) (HKLM\...\Mozilla Firefox 61.0.1 (x64 pt-BR)) (Version: 61.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.2 - Mozilla)
MSI Development Tools (HKLM-x32\...\{1E406B46-65F4-91CE-65DA-DB66D5443B68}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Object Builder (HKLM-x32\...\{6180D897-08AA-E86F-07C1-EA8C67B25692}) (Version: 0.4.5 - UNKNOWN) Hidden
Object Builder (HKLM-x32\...\com.mignari.ObjectBuilder) (Version: 0.4.5 - UNKNOWN)
Origin (HKLM-x32\...\Origin) (Version: 10.5.17.52805 - Electronic Arts, Inc.)
Painel de controle da NVIDIA 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.13 - NVIDIA Corporation) Hidden
Path of Building version 1.4.78 (HKLM-x32\...\{72FA9AB7-189F-4BDE-8856-72DEB90C157B}_is1) (Version: 1.4.78 - Openarl)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.18.115 - Nome de sua empresa:)
SDK ARM Additions (HKLM-x32\...\{346B2C02-CC0D-6E09-8B9D-CAA2821473CF}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
SDK ARM Redistributables (HKLM-x32\...\{825784BB-114D-ADB3-B65F-E1EB2A63C3BC}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
SimCity (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.98.0213 - Electronic Arts)
Stardew Valley (HKLM-x32\...\1453375253_is1) (Version: 2.7.0.9 - GOG.com)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.1.3629 - TeamViewer)
Universal CRT Extension SDK (HKLM-x32\...\{18ABFDF6-23D9-87E6-015E-FFE3C7F153D5}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Headers Libraries and Sources (HKLM-x32\...\{0D6B41AF-D117-8944-A059-3F9346A896C5}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Redistributable (HKLM-x32\...\{B6273353-8B54-1F89-1A16-5940925104CE}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Tools x64 (HKLM\...\{BA6F1D53-C3F2-F9D5-80CE-CEF608E36AD3}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Tools x86 (HKLM-x32\...\{6E43CA0C-046E-4F38-A0A2-3B1BA139B661}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal General MIDI DLS Extension SDK (HKLM-x32\...\{775886B8-DEE1-CB20-8A94-FC09FA54ECF6}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
vcpp_crt.redist.clickonce (HKLM-x32\...\{9F1104D8-0720-45EC-8BD6-24F383CDC134}) (Version: 14.14.26405 - Microsoft Corporation) Hidden
Visual Studio Community 2017 (HKLM-x32\...\ce57fe48) (Version: 15.7.27703.2000 - Microsoft Corporation)
VS Immersive Activate Helper (HKLM-x32\...\{10948144-16FC-42B6-8DEA-5AC2428278DF}) (Version: 16.0.94.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{4D42BCAC-81DD-4450-8BDC-7FCC4C975D2F}) (Version: 16.0.94.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{48C2D1FA-9F23-40E1-9F16-6A3CA6A78915}) (Version: 16.0.94.0 - Microsoft Corporation) Hidden
vs_communitymsi (HKLM-x32\...\{5DFEB1ED-29B8-44F0-8615-DE758242B0E2}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{24128E7F-36B8-4865-9A0B-EF7EBCA46F1E}) (Version: 15.0.26621 - Microsoft Corporation) Hidden
vs_devenvmsi (HKLM-x32\...\{BFFA2FFB-1095-4ADD-A352-368806D2412B}) (Version: 15.0.26621 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{B6600254-A9D1-4265-826B-28B0E28C1F37}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{EF15DAFE-8E43-48E6-AE94-CBA196675318}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{8EB2C670-04C2-482D-BACD-B4095E27FD39}) (Version: 15.6.27309 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx64 (HKLM\...\{B11D79C6-332C-47B6-B58C-2F88A4911C7C}) (Version: 15.0.27005 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx86 (HKLM-x32\...\{2497054A-0269-4F45-98AE-F469F89CC45F}) (Version: 15.0.27005 - Microsoft Corporation) Hidden
vs_minshellinteropmsi (HKLM-x32\...\{9B1DD088-CF09-46A1-8B42-18D231B19E39}) (Version: 15.7.27604 - Microsoft Corporation) Hidden
vs_minshellmsi (HKLM-x32\...\{F5BCAD30-D22C-4B08-A581-1EBE3A35C6B1}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{0E68B234-217C-4534-AB01-3388C5D796F5}) (Version: 15.0.26621 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{1AC6CC3D-7724-4D84-9270-798A2191AB1C}) (Version: 15.0.27005 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WinAppDeploy (HKLM-x32\...\{5AD4A604-B476-1578-2A20-6B02FC6258BE}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Windows Mobile Connectivity Tools 10.0.15254.0 - Desktop x86 (HKLM-x32\...\{833F02C5-2C39-49F6-BD64-91D351081274}) (Version: 10.1.15254.1 - Microsoft Corporation)
Windows SDK AddOn (HKLM-x32\...\{E77C2F78-6089-48F8-89DF-DDF2850DFFD9}) (Version: 10.1.0.0 - Microsoft Corporation)
Windows Software Development Kit - Windows 10.0.17134.12 (HKLM-x32\...\{5f83ccda-0498-4b97-a298-16a642bf49f2}) (Version: 10.1.17134.12 - Microsoft Corporation)
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
WinRT Intellisense Desktop - en-us (HKLM-x32\...\{389D182F-0ADA-5C7E-FF32-2573A821592C}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{C3776B36-B34E-00E2-3009-95A6F1870B58}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - en-us (HKLM-x32\...\{965D1746-D94A-49B9-2A48-A14914CA3B57}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{84C6B91B-67DA-DDE3-86F1-87A3E307E8C1}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense Mobile - en-us (HKLM-x32\...\{3755CD99-C62E-3312-DDD3-29A4F259270D}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - en-us (HKLM-x32\...\{729DA966-8590-2C1F-2178-16C1D32FD7FD}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{F1C18506-3168-A9D9-E2D9-D23A512A326E}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - en-us (HKLM-x32\...\{4095D263-6A13-78D3-DEDA-AA3452011F6E}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{C3243E23-2EB6-4419-2692-40944923B112}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
XAMPP (HKLM-x32\...\xampp) (Version: 7.2.5-0 - Bitnami)

==================== Exame Personalizado CLSID (Whitelisted): ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext32.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext32.dll [2017-08-11] (Alexander Roshal)

==================== Tarefas Agendadas (Whitelisted) =============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {1FCE018D-F084-4B7E-9E2C-38C35EB0B2E8} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {59B4761D-544C-4074-811F-AD33A7546639} - System32\Tasks\{B8A3717B-7F7A-4623-C344-C5DC638D4455} => C:\Program Files (x86)\oijYoXoQIUk.exe [2018-04-11] (Microsoft Corporation) <==== ATENÇÃO
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {69D49877-D21A-4A6E-888D-270B58E898E8} - System32\Tasks\R@1n-KMS\Windows100Professional => wmic [Argument = path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate]
Task: {7C441F15-B847-4205-BD6A-F77F24CFCC4E} - System32\Tasks\CorelUpdateHelperTaskCore => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2018-06-21] (Corel Corporation)
Task: {8872792C-35DF-47C3-9C5B-F8E5A920317E} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-07-19] (AVAST Software)
Task: {95BA7087-8F82-4144-B5E2-05DFBFF87B1C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-19] (Google Inc.)
Task: {974582BC-21EE-47F0-9A86-7D199C230D3D} - System32\Tasks\{F5007D8A-A700-02EA-1ECF-E738E9566150} => C:\Program Files (x86)\Common Files\hCEC.exe [2018-04-11] (Microsoft Corporation)
Task: {A4238E70-129A-4540-8732-A1F2C67AED32} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {BBA49D3D-BD05-472C-8F0C-AA04F7F161D0} - System32\Tasks\{974F87F5-E009-F0AD-8F98-7D4B120EBEB8} => "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://hqfok.com/cl/?guid=j5bez6jjawjofof9fsxi99z6gy1hwzr6&prid=1&pid=4_1324_0
Task: {C13D2FE9-B920-4FFB-AF1A-5AFD955FB7F1} - System32\Tasks\Product Updater => C:\Program Files (x86)\Free Driver Backup\FFProductUpdater.exe
Task: {DECA6DD1-13E0-48EA-9904-BF4CBCB8EFC3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-19] (Google Inc.)
Task: {FC3B8A5D-2583-498E-BE0A-B0FCB06A5F08} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-07-19] (AVAST Software)

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Atalhos & WMI ========================

(As entradas podem ser listadas para serem restauradas ou removidas.)


==================== Módulos Carregados (Whitelisted) ==============

2018-04-11 20:34 - 2018-04-11 20:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 20:34 - 2018-04-11 20:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 20:34 - 2018-04-11 20:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-07-10 15:59 - 2018-07-06 03:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll

==================== Alternate Data Streams (Whitelisted) =========

==================== Modo de Segurança (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Associação (Whitelisted) ===============

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.)


==================== Internet Explorer confiável/restrito ===============

(Se uma entrada for incluída na fixlist, será removida do Registro.)


==================== Hosts Conteúdo: ===============================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2017-09-29 10:46 - 2017-09-29 10:44 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Outras Áreas ============================

(Atualmente não há nenhuma correção automática para esta seção.)

HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: O Suporte não está conectado à internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Firewall do Windows está habilitado.

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==


==================== Regras do Firewall (Whitelisted) ===============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [UDP Query User{BC033C90-AF3F-4F51-A8D2-22BC564A3B66}D:\pxg\testglobal\server\theforgottenserver.exe] => (Allow) D:\pxg\testglobal\server\theforgottenserver.exe
FirewallRules: [TCP Query User{BD21D8E0-EAAC-4E83-951D-026C75453763}D:\pxg\testglobal\server\theforgottenserver.exe] => (Allow) D:\pxg\testglobal\server\theforgottenserver.exe
FirewallRules: [UDP Query User{B813507D-1D37-4D2E-920C-8CD6D05ADA03}D:\pxg\proffision\servidor\servidor.exe] => (Allow) D:\pxg\proffision\servidor\servidor.exe
FirewallRules: [TCP Query User{3D589472-4207-4A66-8784-32E144A113A4}D:\pxg\proffision\servidor\servidor.exe] => (Allow) D:\pxg\proffision\servidor\servidor.exe
FirewallRules: [UDP Query User{F463EB58-BAD5-4BEB-800D-DF5B925E51E9}D:\pxg\novim\server\theforgottenserver.exe] => (Allow) D:\pxg\novim\server\theforgottenserver.exe
FirewallRules: [TCP Query User{FAEEE956-653E-4493-BDB3-5077BEBF83C0}D:\pxg\novim\server\theforgottenserver.exe] => (Allow) D:\pxg\novim\server\theforgottenserver.exe
FirewallRules: [UDP Query User{4AB92810-01E4-4A67-AD50-BCB457887036}D:\pxg\rubyserver-master\therubyserver.exe] => (Allow) D:\pxg\rubyserver-master\therubyserver.exe
FirewallRules: [TCP Query User{1A3B52E2-5131-433E-A7D4-582E8B0A7CDB}D:\pxg\rubyserver-master\therubyserver.exe] => (Allow) D:\pxg\rubyserver-master\therubyserver.exe
FirewallRules: [UDP Query User{EDC72A73-048D-4BCF-B5CA-E2D9ABCCB5EC}D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe] => (Allow) D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe
FirewallRules: [TCP Query User{69406ED4-0F3B-464B-AF82-EE5840F2741F}D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe] => (Allow) D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe
FirewallRules: [UDP Query User{CB5A8E0E-12A4-4154-B6E7-295DBDAF06FC}D:\pxg\server poek pa\pokeserver\theforgottenserver.exe] => (Allow) D:\pxg\server poek pa\pokeserver\theforgottenserver.exe
FirewallRules: [TCP Query User{0E42BDEB-C071-4152-BF28-86CF5E017A77}D:\pxg\server poek pa\pokeserver\theforgottenserver.exe] => (Allow) D:\pxg\server poek pa\pokeserver\theforgottenserver.exe
FirewallRules: [UDP Query User{D3CCE180-4F7D-4539-9990-F06B4F0A6BA5}D:\xampp\mysql\bin\mysqld.exe] => (Allow) D:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{31CEB48D-B4F6-42CE-BBF4-28AFF63B9BF2}D:\xampp\mysql\bin\mysqld.exe] => (Allow) D:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{3A65E21B-8E30-44C4-A75E-EC8ABB22ABE5}D:\xampp\apache\bin\httpd.exe] => (Allow) D:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{7BC98DC9-74F7-43B6-8076-5FE2CB200FA3}D:\xampp\apache\bin\httpd.exe] => (Allow) D:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{B63AC3A2-FC19-4254-B100-C97697DB9CE2}D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe
FirewallRules: [TCP Query User{5C43D0A3-1AF7-410D-9EEB-7FC41255FDED}D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe
FirewallRules: [UDP Query User{1EEE87E7-C5D7-436C-8DFD-2AB519F45A8F}D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe] => (Allow) D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe
FirewallRules: [TCP Query User{6CFEA1CB-BFD8-4DD8-A5F9-F56D7494DDFE}D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe] => (Allow) D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe
FirewallRules: [{363BCEFC-8095-40B2-AD94-3BBDF9BA794F}] => (Allow) C:\Users\Matheus Zanutto\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E4541927-6693-4CB4-9AD9-AB451A51A6CF}] => (Allow) C:\Users\Matheus Zanutto\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D6003D07-051C-4A2D-B56B-9ED9897E1593}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{2539443C-9A6D-41FD-960F-E0D4941F4B57}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{B2011AD2-30BA-42C7-AEBA-3BA07E13CFEE}] => (Allow) D:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{559AF488-FC48-4079-B0C8-9F8DC508802C}] => (Allow) D:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [UDP Query User{F1C44D2A-9269-48D5-BCAB-9F3866D9626A}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{1CDDB99D-344C-48D5-8E61-7A1D63A6F4C7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{BE2EE86E-CB6C-44D3-9A8C-FA47F639DA91}] => (Allow) C:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE68BCCD-1AAB-4CA9-9799-AA193E782DD5}] => (Allow) C:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{33736E1D-06E8-496D-89D2-1AF5ECC84D29}] => (Allow) C:\SteamLibrary\steamapps\common\Path of Exile\PathOfExileSteam.exe
FirewallRules: [{EDE789AB-E466-4162-9ADE-4D941360B013}] => (Allow) C:\SteamLibrary\steamapps\common\Path of Exile\PathOfExileSteam.exe
FirewallRules: [{BBED1A47-25B4-43A4-8691-DB3D2AD73B56}] => (Block) D:\CorelDRAW Graphics Suite X8\Programs64\CdrConv.exe
FirewallRules: [{D38ED28E-4AB8-4C02-B507-D5A5FEAD3B3A}] => (Block) D:\CorelDRAW Graphics Suite X8\Programs64\CorelPP.exe
FirewallRules: [{B07D321B-81B8-4B40-81CB-0B6371717DB0}] => (Block) D:\CorelDRAW Graphics Suite X8\Programs64\CorelDRW.exe
FirewallRules: [{EF94DD69-16B5-42A4-80F7-F348AE0B5D70}] => (Block) d:\CorelDRAW Graphics Suite X8\Programs64\CorelPP.exe
FirewallRules: [{0734B79D-2908-4ACC-8BA2-1BB69ABA361F}] => (Block) d:\CorelDRAW Graphics Suite X8\Programs64\CorelDrw.exe
FirewallRules: [{4C89A848-F602-499C-8C32-13F5F9FC54D0}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F6D0CB2A-2F8B-4CEB-B618-4A077AA88E7F}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{595C5865-053C-455F-9BE9-93A9CF64C540}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{331A2530-B1DF-469D-AB0B-127BBD801BB9}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{A5D4487E-612D-4ABA-9608-1CEFF077E98F}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{232D5C0D-06B2-46E9-97C8-AEF9C3855DD8}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{C4D4C7C7-5317-4BBB-8F78-159156A59E3B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{F15B01F2-4FA8-46D2-B1A2-87472255D342}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{ABC9A59C-B25E-43F0-907E-E71AE7128213}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{B0BFBAB2-1235-42FC-A07B-767248E61410}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{F33DB86F-0046-46B4-A88F-15D5FF5FAE28}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{F556E6A5-FAF2-45FC-86E9-D47543EDBCBC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{68E1F4F5-7726-4F4F-A953-5030669354F6}] => (Allow) D:\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe
FirewallRules: [{1CDED122-F1DA-4EB0-B743-C3F6665145FD}] => (Allow) D:\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe
FirewallRules: [TCP Query User{67D75185-E223-4002-A9D7-BDE786AA93DB}D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe
FirewallRules: [UDP Query User{1E791C73-62D4-4B36-9F62-A9BD74A4587D}D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe
FirewallRules: [{6047D139-E12B-4E93-9A65-556539A34B76}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{66241F6E-8056-41C3-8039-468EACD57034}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{0291AE34-15CC-4BAB-8146-1578131B85D7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{94AF8459-6E8D-46F6-ACC5-54C3D632DCD4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{AD6F31A9-32C1-4FC6-B595-B7EC808A3EBA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{D9598AB7-0FBA-4BC6-A7A0-32803EEA2392}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{C45BD4E7-F9D5-464D-9778-0989438BCE10}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{D3DE5333-B930-4E92-8C23-5603C6CF12BC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{52BA74CF-53C6-453C-8230-058E8E27D53D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
FirewallRules: [{16611E6B-9D88-46F6-AD16-2890A49F81CE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
FirewallRules: [TCP Query User{1F6E5984-16AB-4991-8723-0047591177FC}D:\jdownloader\jdownloader v2.0\jdownloader2.exe] => (Allow) D:\jdownloader\jdownloader v2.0\jdownloader2.exe
FirewallRules: [UDP Query User{A94F5F23-F789-48C0-AE2D-BDFD5E1DD3D3}D:\jdownloader\jdownloader v2.0\jdownloader2.exe] => (Allow) D:\jdownloader\jdownloader v2.0\jdownloader2.exe
FirewallRules: [TCP Query User{7902AD59-6AAF-4269-BD22-48F5BB811AB5}D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe
FirewallRules: [UDP Query User{2420BE31-D32A-4273-9FD8-6B9C0641FF9F}D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe
FirewallRules: [{4169313C-0763-43CE-A4E0-CDF8983B24E9}] => (Allow) C:\WINDOWS\SysWOW64\msiexec.exe
FirewallRules: [{045BEA7E-EC86-4C3E-B48C-E8440FFF7CCE}] => (Allow) C:\Program Files (x86)\oijYoXoQIUk.exe
FirewallRules: [{A363F146-6458-4E55-84CF-81381EC73E9E}] => (Allow) C:\Program Files (x86)\Common Files\hCEC.exe
FirewallRules: [{FAD1770A-0D6B-44DC-A9E0-7C8E23FB9330}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{EA0ACB89-93A0-4FEA-8BBF-963112CE4333}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{26EF3551-CD14-48B5-83D8-74B7B2BFDE16}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{41A23472-4432-435A-BD49-453BD26B3C34}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{DEE8E28B-9960-4150-ABD4-2BE6332ACB8A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E346A14D-E64D-4EE8-9E97-CF61400D8ECB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{9DC1E53E-264E-4E6D-9B73-EF8E6734AA92}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{4AE125DE-46A8-4C1E-8081-24A54E3F496D}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{F0C45DFE-B37B-43BE-968E-004EBA1E099A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{565B8AB7-B7D5-4E57-8A1F-08378DF11651}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{9250ACA9-FFD6-4D94-BDB3-92FEAA2EB220}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{D9FD64EA-2687-43D2-9011-44B43724F25D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{C3D7A33F-94E3-43BF-BB08-EC371F669A51}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe

==================== Pontos de Restauração =========================

ATENÇÃO: A Restauração do Sistema está desabilitada

==================== Dispositivos Apresentando Falhas No Gerenciador =============

Name: NVIDIA High Definition Audio
Description: NVIDIA High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: NVHDA
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Erros no Log de eventos: =========================

Erros em Aplicativos:
==================
Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:46:58 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:39:32 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.


Erros de Sistema:
=============
Error: (07/19/2018 05:54:21 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:54:05 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:53 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:40 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:35 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:32 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço TokenBroker com argumentos "Não Disponível" para executar o servidor:
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal

Error: (07/19/2018 05:53:31 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço WSearch com argumentos "Não Disponível" para executar o servidor:
{E48EDA45-43C6-48E0-9323-A7B2067D9CD5}

Error: (07/19/2018 05:53:27 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}


Windows Defender:
===================================
Date: 2018-07-19 16:11:06.932
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Zpevdo.A&threatid=2147727143&enterprise=0
Nome: Trojan:Win32/Zpevdo.A
ID: 2147727143
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\Desktop\jailbreak-exploit_11.4.1-3\exploit_v3.exe
Origem da Detecção: Computador local
Tipo de Detecção: FastPath
Origem da Detecção: Sistema
Usuário: AUTORIDADE NT\SISTEMA
Nome do Processo: C:\Windows\System32\consent.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 16:11:03.243
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Zpevdo.A&threatid=2147727143&enterprise=0
Nome: Trojan:Win32/Zpevdo.A
ID: 2147727143
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\Desktop\jailbreak-exploit_11.4.1-3\exploit_v3.exe
Origem da Detecção: Computador local
Tipo de Detecção: FastPath
Origem da Detecção: Sistema
Usuário: AUTORIDADE NT\SISTEMA
Nome do Processo: Unknown
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 14:20:59.775
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Brocoiner!rfn&threatid=2147724297&enterprise=0
Nome: Trojan:HTML/Brocoiner!rfn
ID: 2147724297
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\AppData\Local\Mozilla\Firefox\Profiles\214l4ozi.default\cache2\entries\CE94BF5164C04AE312403C4CA6A85F4F3B1133A2
Origem da Detecção: Computador local
Tipo de Detecção: Concreto
Origem da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-Q3D5SVE\Matheus Zanutto
Nome do Processo: C:\Program Files\Mozilla Firefox\firefox.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 14:20:41.034
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Brocoiner!rfn&threatid=2147724297&enterprise=0
Nome: Trojan:HTML/Brocoiner!rfn
ID: 2147724297
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\AppData\Local\Mozilla\Firefox\Profiles\214l4ozi.default\cache2\entries\CE94BF5164C04AE312403C4CA6A85F4F3B1133A2
Origem da Detecção: Computador local
Tipo de Detecção: Concreto
Origem da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-Q3D5SVE\Matheus Zanutto
Nome do Processo: C:\Program Files\Mozilla Firefox\firefox.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 14:20:32.021
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Brocoiner!rfn&threatid=2147724297&enterprise=0
Nome: Trojan:HTML/Brocoiner!rfn
ID: 2147724297
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\AppData\Local\Mozilla\Firefox\Profiles\214l4ozi.default\cache2\entries\CE94BF5164C04AE312403C4CA6A85F4F3B1133A2
Origem da Detecção: Computador local
Tipo de Detecção: Concreto
Origem da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-Q3D5SVE\Matheus Zanutto
Nome do Processo: C:\Program Files\Mozilla Firefox\firefox.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

==================== Informações da Memória ===========================

Processador: Intel® Core™ i7-3770 CPU @ 3.40GHz
Percentagem de memória em uso: 8%
RAM física total: 12266.4 MB
RAM física disponível: 11182.75 MB
Virtual Total: 16362.4 MB
Virtual disponível: 15498.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.22 GB) (Free:41.91 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:688.37 GB) NTFS

\\?\Volume{fa16dff0-0000-0000-0000-100000000000}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
\\?\Volume{fa16dff0-0000-0000-0000-30d41b000000}\ () (Fixed) (Total:0.47 GB) (Free:0.08 GB) NTFS

==================== MBR & Tabela de Partições ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: FA16DFF0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=484 MB) - (Type=27)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 360A2C64)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== Fim de Addition.txt ============================
Ps: I can only run the FRST in security mode

#3 Matszg

Matszg
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  

Posted 19 July 2018 - 04:05 PM

This is the FRST.log
Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 15.07.2018
Executado por Matheus Zanutto (administrador) em DESKTOP-Q3D5SVE (19-07-2018 17:53:52)
Executando a partir de D:\Downloads
Perfis Carregados: Matheus Zanutto (Perfis Disponíveis: Matheus Zanutto)
Platform: Windows 10 Pro Versão 1803 17134.165 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: FF)
Modo da Inicialização: Safe Mode (with Networking)
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-07-19] (AVAST Software)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596664 2018-01-15] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\Run: [Steam] => D:\Steam\steam.exe [3201312 2018-06-08] (Valve Corporation)
HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\Run: [Discord] => C:\Users\Matheus Zanutto\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\RunOnce: [Application Restart #0] => C:\Windows\System32\Taskmgr.exe [1326952 2018-04-11] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk [2018-04-09]
ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.)
Startup: C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitorar alertas de tinta - HP Deskjet 1510 series.lnk [2018-07-19]
ShortcutTarget: Monitorar alertas de tinta - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\..\Interfaces\{38306256-5543-4ed7-aba6-fa6614866829}: [DhcpNameServer] 208.67.222.222 208.67.220.220

Internet Explorer:
==================
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-05-11] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-05-11] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 214l4ozi.default
FF ProfilePath: C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default [2018-07-19]
FF Homepage: Mozilla\Firefox\Profiles\214l4ozi.default -> about:home
FF Extension: (MyJDownloader Browser Extension) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\jid1-OY8Xu5BsKZQa6A@jetpack.xpi [2018-07-17]
FF Extension: (uBlock Origin) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\uBlock0@raymondhill.net.xpi [2018-07-18]
FF Extension: (Avast Online Security) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\wrc@avast.com.xpi [2018-07-19]
FF Extension: (openwpdf) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\{2582ab30-4fca-475f-88d0-c1a9b9ed978f}.xpi [2018-04-08]
FF Extension: (Video DownloadHelper) - C:\Users\Matheus Zanutto\AppData\Roaming\Mozilla\Firefox\Profiles\214l4ozi.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-07-12]
FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2018-07-12] [Legacy] [não assinado]
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-05-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-05-11] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-19] (Google Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default [2018-07-19]
CHR Extension: (Apresentações) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-19]
CHR Extension: (Documentos) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-19]
CHR Extension: (Google Drive) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-19]
CHR Extension: (YouTube) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-19]
CHR Extension: (Planilhas) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-19]
CHR Extension: (Documentos Google off-line) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-19]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-19]
CHR Extension: (Gmail) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-19]
CHR Extension: (Chrome Media Router) - C:\Users\Matheus Zanutto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-19]

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7780400 2018-07-19] (AVAST Software)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-07-19] (AVAST Software)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Arquivo não assinado]
S2 Intel® PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [505856 2018-01-31] (Intel Corporation) [Arquivo não assinado]
S2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2018-04-08] () [Arquivo não assinado]
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2158912 2018-04-23] (Electronic Arts)
S2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [3028808 2018-04-23] (Electronic Arts)
S2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2017-07-19] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
S3 VSStandardCollectorService150; D:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [145512 2018-01-23] (Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
S2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (Apple Inc.)
S1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [197160 2018-07-19] (AVAST Software)
S1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [229392 2018-07-19] (AVAST Software)
S0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [201328 2018-07-19] (AVAST Software)
S0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [346664 2018-07-19] (AVAST Software)
S0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [59592 2018-07-19] (AVAST Software)
S3 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15360 2018-07-19] (AVAST Software)
S1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [239680 2018-07-19] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46976 2018-07-19] (AVAST Software)
S2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [159640 2018-07-19] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111872 2018-07-19] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [85968 2018-07-19] (AVAST Software)
S1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1027728 2018-07-19] (AVAST Software)
S1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [463080 2018-07-19] (AVAST Software)
S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [211160 2018-07-19] (AVAST Software)
S0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [381584 2018-07-19] (AVAST Software)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30352 2018-04-08] (Disc Soft Ltd)
R3 e1cexpress; C:\WINDOWS\system32\DRIVERS\e1c65x64.sys [472016 2016-07-18] (Intel Corporation)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
S3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_desktop_ref4wu.inf_amd64_0109a19b5125cb43\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc)
S2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [45752 2017-07-19] (Razer, Inc.)
S2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [139704 2017-08-19] (Razer, Inc.)
S3 smbdirect; C:\WINDOWS\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2018-07-19 17:53 - 2018-07-19 17:53 - 000000000 ____D C:\FRST
2018-07-19 16:45 - 2018-07-19 16:45 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-07-19 16:45 - 2018-07-19 16:45 - 000002334 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-07-19 16:44 - 2018-07-19 16:49 - 000003588 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-07-19 16:44 - 2018-07-19 16:49 - 000003464 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-07-19 16:44 - 2018-07-19 16:45 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\Google
2018-07-19 16:44 - 2018-07-19 16:45 - 000000000 ____D C:\Program Files (x86)\Google
2018-07-19 16:43 - 2018-07-19 16:57 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\AVAST Software
2018-07-19 16:43 - 2018-07-19 16:43 - 000001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2018-07-19 16:43 - 2018-07-19 16:43 - 000001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2018-07-19 16:43 - 2018-07-19 16:43 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\AVAST Software
2018-07-19 16:37 - 2018-07-19 17:53 - 000646276 _____ C:\WINDOWS\ntbtlog.txt
2018-07-19 16:37 - 2018-07-19 17:52 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2018-07-19 16:33 - 2018-07-19 16:33 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software
2018-07-19 16:32 - 2018-07-19 16:32 - 001027728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000463080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000381584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000378072 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-07-19 16:32 - 2018-07-19 16:32 - 000346664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000239680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000229392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000211160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000201328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000197160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000159640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000111872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000085968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000059592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000046976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000015360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2018-07-19 16:32 - 2018-07-19 16:32 - 000003990 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2018-07-19 16:32 - 2018-07-19 16:32 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2018-07-19 16:30 - 2018-07-19 16:32 - 000000000 ____D C:\Users\Todos os Usuários\AVAST Software
2018-07-19 16:30 - 2018-07-19 16:32 - 000000000 ____D C:\ProgramData\AVAST Software
2018-07-19 16:30 - 2018-07-19 16:30 - 000000000 ____D C:\Program Files\AVAST Software
2018-07-19 14:18 - 2018-07-19 14:18 - 000003908 _____ C:\WINDOWS\System32\Tasks\{974F87F5-E009-F0AD-8F98-7D4B120EBEB8}
2018-07-19 14:18 - 2018-07-19 14:18 - 000003822 _____ C:\WINDOWS\System32\Tasks\{B8A3717B-7F7A-4623-C344-C5DC638D4455}
2018-07-19 14:18 - 2018-07-19 14:18 - 000003634 _____ C:\WINDOWS\System32\Tasks\{F5007D8A-A700-02EA-1ECF-E738E9566150}
2018-07-19 14:18 - 2018-07-19 14:18 - 000000002 _____ C:\Users\Matheus Zanutto\AppData\Local\imw.ini
2018-07-10 15:59 - 2018-07-06 11:20 - 001610648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-07-10 15:59 - 2018-07-06 11:20 - 000689560 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-07-10 15:59 - 2018-07-06 11:15 - 002266520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2018-07-10 15:59 - 2018-07-06 10:56 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-07-10 15:59 - 2018-07-06 10:51 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-07-10 15:59 - 2018-07-06 09:12 - 001539000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2018-07-10 15:59 - 2018-07-06 08:26 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-07-10 15:59 - 2018-07-06 08:25 - 023863296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-07-10 15:59 - 2018-07-06 04:31 - 000462752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-07-10 15:59 - 2018-07-06 04:25 - 009147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-07-10 15:59 - 2018-07-06 04:10 - 025845760 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-07-10 15:59 - 2018-07-06 04:07 - 022006272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-07-10 15:59 - 2018-07-06 04:04 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-07-10 15:59 - 2018-07-06 04:03 - 004371456 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-07-10 15:59 - 2018-07-06 04:02 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2018-07-10 15:59 - 2018-07-06 04:01 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2018-07-10 15:59 - 2018-07-06 04:00 - 019403264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-07-10 15:59 - 2018-07-06 03:58 - 004867584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-07-10 15:59 - 2018-07-06 03:57 - 007579648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-07-10 15:59 - 2018-07-06 03:57 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-07-10 15:59 - 2018-07-06 03:56 - 001817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-07-10 15:59 - 2018-07-06 03:55 - 003440128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-07-10 15:59 - 2018-06-15 14:49 - 021388856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-07-10 15:59 - 2018-06-15 14:33 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-07-10 15:59 - 2018-06-15 12:25 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-07-10 15:59 - 2018-06-15 12:07 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-07-10 15:59 - 2018-06-15 02:21 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-07-10 15:59 - 2018-06-15 02:12 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-07-10 15:59 - 2018-06-15 02:11 - 006817872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-07-10 15:59 - 2018-06-15 02:09 - 007436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-07-10 15:59 - 2018-06-15 02:09 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 004403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-07-10 15:59 - 2018-06-15 02:08 - 001288840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-07-10 15:59 - 2018-06-15 02:07 - 001611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-07-10 15:59 - 2018-06-15 02:07 - 001145696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2018-07-10 15:59 - 2018-06-15 02:04 - 002331576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 006572000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 006528600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 006043600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 004788504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 001710240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 001144120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2018-07-10 15:59 - 2018-06-15 02:03 - 001020160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-07-10 15:59 - 2018-06-15 01:46 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-07-10 15:59 - 2018-06-15 01:44 - 005746688 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2018-07-10 15:59 - 2018-06-15 01:42 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-07-10 15:59 - 2018-06-15 01:42 - 002367488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-07-10 15:59 - 2018-06-15 01:41 - 004561920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 002868640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-07-10 15:58 - 2018-07-06 11:20 - 000792472 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000451992 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000309664 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-07-10 15:58 - 2018-07-06 11:20 - 000144792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-07-10 15:58 - 2018-07-06 11:20 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-07-10 15:58 - 2018-07-06 11:17 - 003932672 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-07-10 15:58 - 2018-07-06 11:14 - 000541592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000672768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-07-10 15:58 - 2018-07-06 10:53 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-07-10 15:58 - 2018-07-06 10:52 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-07-10 15:58 - 2018-07-06 10:52 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-07-10 15:58 - 2018-07-06 10:51 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-07-10 15:58 - 2018-07-06 10:51 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-07-10 15:58 - 2018-07-06 10:51 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-07-10 15:58 - 2018-07-06 10:51 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-07-10 15:58 - 2018-07-06 10:50 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-07-10 15:58 - 2018-07-06 10:49 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-07-10 15:58 - 2018-07-06 09:06 - 003611368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-07-10 15:58 - 2018-07-06 08:54 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-07-10 15:58 - 2018-07-06 08:54 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-07-10 15:58 - 2018-07-06 08:53 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-07-10 15:58 - 2018-07-06 08:53 - 000565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2018-07-10 15:58 - 2018-07-06 08:53 - 000347136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-07-10 15:58 - 2018-07-06 08:52 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-07-10 15:58 - 2018-07-06 08:52 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-07-10 15:58 - 2018-07-06 08:52 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-07-10 15:58 - 2018-07-06 08:51 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-07-10 15:58 - 2018-07-06 08:51 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-07-10 15:58 - 2018-07-06 08:01 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-07-10 15:58 - 2018-07-06 04:32 - 000480672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-07-10 15:58 - 2018-07-06 04:31 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-07-10 15:58 - 2018-07-06 04:29 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-07-10 15:58 - 2018-07-06 04:29 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-07-10 15:58 - 2018-07-06 04:27 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-07-10 15:58 - 2018-07-06 04:27 - 001063320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-07-10 15:58 - 2018-07-06 04:27 - 001012632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-07-10 15:58 - 2018-07-06 04:27 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-07-10 15:58 - 2018-07-06 04:27 - 000567176 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-07-10 15:58 - 2018-07-06 04:27 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-07-10 15:58 - 2018-07-06 04:27 - 000057440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2018-07-10 15:58 - 2018-07-06 04:26 - 002712992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-07-10 15:58 - 2018-07-06 04:26 - 001148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-07-10 15:58 - 2018-07-06 04:26 - 000930720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-07-10 15:58 - 2018-07-06 04:26 - 000766608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2018-07-10 15:58 - 2018-07-06 04:26 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-07-10 15:58 - 2018-07-06 04:25 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 002571728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 002420632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-07-10 15:58 - 2018-07-06 04:25 - 001945784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 001026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-07-10 15:58 - 2018-07-06 04:25 - 001018616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000885856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000483048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000267680 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-07-10 15:58 - 2018-07-06 04:25 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2018-07-10 15:58 - 2018-07-06 04:24 - 000380824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-07-10 15:58 - 2018-07-06 04:16 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 001981896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 001175568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 000988640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-07-10 15:58 - 2018-07-06 04:14 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-07-10 15:58 - 2018-07-06 04:14 - 000573904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2018-07-10 15:58 - 2018-07-06 04:13 - 001620872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-07-10 15:58 - 2018-07-06 04:01 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2018-07-10 15:58 - 2018-07-06 04:01 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2018-07-10 15:58 - 2018-07-06 04:01 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsTelemetry.dll
2018-07-10 15:58 - 2018-07-06 04:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 001153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2018-07-10 15:58 - 2018-07-06 03:59 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 001931776 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2018-07-10 15:58 - 2018-07-06 03:58 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-07-10 15:58 - 2018-07-06 03:58 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000676864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2018-07-10 15:58 - 2018-07-06 03:57 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-07-10 15:58 - 2018-07-06 03:56 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-07-10 15:58 - 2018-07-06 03:55 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 003015680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-07-10 15:58 - 2018-07-06 03:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2018-07-10 15:58 - 2018-07-06 03:54 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2018-07-10 15:58 - 2018-07-06 03:53 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2018-07-10 15:58 - 2018-07-06 03:52 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-07-10 15:58 - 2018-07-06 02:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-07-10 15:58 - 2018-06-29 01:16 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-10 15:58 - 2018-06-15 14:55 - 000542888 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2018-07-10 15:58 - 2018-06-15 14:53 - 000348256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-07-10 15:58 - 2018-06-15 14:53 - 000094104 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-07-10 15:58 - 2018-06-15 14:50 - 001376576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-07-10 15:58 - 2018-06-15 14:48 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-07-10 15:58 - 2018-06-15 14:48 - 000338352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2018-07-10 15:58 - 2018-06-15 14:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-07-10 15:58 - 2018-06-15 14:34 - 008623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-07-10 15:58 - 2018-06-15 14:34 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2018-07-10 15:58 - 2018-06-15 14:34 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2018-07-10 15:58 - 2018-06-15 14:33 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2018-07-10 15:58 - 2018-06-15 14:33 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
2018-07-10 15:58 - 2018-06-15 14:33 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-10 15:58 - 2018-06-15 14:32 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
2018-07-10 15:58 - 2018-06-15 14:32 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
2018-07-10 15:58 - 2018-06-15 14:32 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2018-07-10 15:58 - 2018-06-15 14:32 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2018-07-10 15:58 - 2018-06-15 14:31 - 002193920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2018-07-10 15:58 - 2018-06-15 14:31 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-07-10 15:58 - 2018-06-15 14:31 - 000907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\autofmt.exe
2018-07-10 15:58 - 2018-06-15 14:31 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 001308672 _____ C:\WINDOWS\system32\FaceProcessor.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 001254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 001186816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-07-10 15:58 - 2018-06-15 14:30 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2018-07-10 15:58 - 2018-06-15 14:30 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
2018-07-10 15:58 - 2018-06-15 14:29 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-07-10 15:58 - 2018-06-15 14:29 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
2018-07-10 15:58 - 2018-06-15 14:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-07-10 15:58 - 2018-06-15 14:29 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-07-10 15:58 - 2018-06-15 14:29 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2018-07-10 15:58 - 2018-06-15 14:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSoftwareInstallationClient.dll
2018-07-10 15:58 - 2018-06-15 14:28 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2018-07-10 15:58 - 2018-06-15 14:28 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2018-07-10 15:58 - 2018-06-15 14:03 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe
2018-07-10 15:58 - 2018-06-15 14:00 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
2018-07-10 15:58 - 2018-06-15 12:22 - 001026896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-07-10 15:58 - 2018-06-15 12:16 - 002206528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-07-10 15:58 - 2018-06-15 12:06 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-07-10 15:58 - 2018-06-15 12:06 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2018-07-10 15:58 - 2018-06-15 12:04 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
2018-07-10 15:58 - 2018-06-15 12:04 - 000373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2018-07-10 15:58 - 2018-06-15 12:03 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autofmt.exe
2018-07-10 15:58 - 2018-06-15 12:03 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-07-10 15:58 - 2018-06-15 12:02 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-07-10 15:58 - 2018-06-15 12:01 - 002015744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-07-10 15:58 - 2018-06-15 12:01 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2018-07-10 15:58 - 2018-06-15 10:23 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-07-10 15:58 - 2018-06-15 04:11 - 000611232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-07-10 15:58 - 2018-06-15 04:10 - 000048544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-07-10 15:58 - 2018-06-15 04:03 - 000083360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-07-10 15:58 - 2018-06-15 02:21 - 000761440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-07-10 15:58 - 2018-06-15 02:19 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-07-10 15:58 - 2018-06-15 02:19 - 000116632 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2018-07-10 15:58 - 2018-06-15 02:19 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-07-10 15:58 - 2018-06-15 02:18 - 000228768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-07-10 15:58 - 2018-06-15 02:16 - 000562080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-07-10 15:58 - 2018-06-15 02:16 - 000433560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-07-10 15:58 - 2018-06-15 02:15 - 002563960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:15 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-07-10 15:58 - 2018-06-15 02:13 - 000510904 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2018-07-10 15:58 - 2018-06-15 02:13 - 000324000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000661152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000491304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-07-10 15:58 - 2018-06-15 02:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 001097640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2018-07-10 15:58 - 2018-06-15 02:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-07-10 15:58 - 2018-06-15 02:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-07-10 15:58 - 2018-06-15 02:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-07-10 15:58 - 2018-06-15 02:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2018-07-10 15:58 - 2018-06-15 02:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-07-10 15:58 - 2018-06-15 02:08 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-07-10 15:58 - 2018-06-15 02:08 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-07-10 15:58 - 2018-06-15 02:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-07-10 15:58 - 2018-06-15 02:08 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-07-10 15:58 - 2018-06-15 02:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-07-10 15:58 - 2018-06-15 02:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-07-10 15:58 - 2018-06-15 02:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-07-10 15:58 - 2018-06-15 02:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2018-07-10 15:58 - 2018-06-15 02:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-07-10 15:58 - 2018-06-15 02:05 - 000444240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2018-07-10 15:58 - 2018-06-15 02:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001380192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-07-10 15:58 - 2018-06-15 02:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2018-07-10 15:58 - 2018-06-15 02:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-07-10 15:58 - 2018-06-15 01:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-07-10 15:58 - 2018-06-15 01:48 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-07-10 15:58 - 2018-06-15 01:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-07-10 15:58 - 2018-06-15 01:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2018-07-10 15:58 - 2018-06-15 01:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2018-07-10 15:58 - 2018-06-15 01:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 004529664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2018-07-10 15:58 - 2018-06-15 01:46 - 004333568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2018-07-10 15:58 - 2018-06-15 01:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 002548736 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2018-07-10 15:58 - 2018-06-15 01:45 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2018-07-10 15:58 - 2018-06-15 01:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2018-07-10 15:58 - 2018-06-15 01:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 001632256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2018-07-10 15:58 - 2018-06-15 01:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-07-10 15:58 - 2018-06-15 01:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-07-10 15:58 - 2018-06-15 01:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2018-07-10 15:58 - 2018-06-15 01:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2018-07-10 15:58 - 2018-06-15 01:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-07-10 15:58 - 2018-06-15 01:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-07-10 15:58 - 2018-06-15 01:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-07-10 15:58 - 2018-06-15 01:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2018-07-10 15:58 - 2018-06-15 01:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2018-07-10 15:58 - 2018-06-15 01:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-07-10 15:58 - 2018-06-15 01:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-07-10 15:58 - 2018-06-15 01:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 002903040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-07-10 15:58 - 2018-06-15 01:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2018-07-10 15:58 - 2018-06-15 01:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-07-10 15:58 - 2018-06-15 01:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-07-10 15:58 - 2018-06-15 01:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-07-10 15:58 - 2018-06-15 01:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
2018-07-10 15:58 - 2018-06-01 02:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
2018-07-10 15:58 - 2018-05-20 08:53 - 000792984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-07-10 15:58 - 2018-05-20 08:52 - 000413080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-06-27 14:17 - 2018-06-27 14:17 - 000002454 _____ C:\Users\Matheus Zanutto\Desktop\CurrencyCop.lnk
2018-06-27 14:17 - 2018-06-27 14:17 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nijiko Yonskai
2018-06-26 14:09 - 2018-06-26 14:09 - 000000202 _____ C:\Users\Matheus Zanutto\Desktop\Realm Royale.url
2018-06-22 16:26 - 2018-06-22 16:26 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\LocalLow\Temp
2018-06-20 10:29 - 2018-07-19 17:07 - 000000000 ____D C:\Users\Todos os Usuários\Packages
2018-06-20 10:29 - 2018-07-19 17:07 - 000000000 ____D C:\ProgramData\Packages

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2018-07-19 17:52 - 2018-04-11 18:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-19 17:51 - 2018-05-22 04:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-19 17:41 - 2018-04-08 13:27 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\LocalLow\Mozilla
2018-07-19 17:33 - 2018-05-22 04:04 - 001737602 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-07-19 17:33 - 2018-04-12 13:37 - 000750582 _____ C:\WINDOWS\system32\prfh0416.dat
2018-07-19 17:33 - 2018-04-12 13:37 - 000147916 _____ C:\WINDOWS\system32\prfc0416.dat
2018-07-19 17:33 - 2018-04-11 20:36 - 000000000 ____D C:\WINDOWS\INF
2018-07-19 17:27 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-19 17:26 - 2018-05-22 05:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-07-19 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft
2018-07-19 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-19 17:26 - 2018-04-08 13:58 - 000000000 ____D C:\Users\Todos os Usuários\NVIDIA
2018-07-19 17:26 - 2018-04-08 13:58 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-19 17:20 - 2018-04-11 20:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-07-19 17:07 - 2018-04-11 20:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-19 16:43 - 2018-04-08 13:20 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\VirtualStore
2018-07-19 16:42 - 2018-05-22 03:56 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-07-19 16:38 - 2018-05-22 04:22 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\ElevatedDiagnostics
2018-07-19 16:32 - 2018-04-11 20:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-07-19 16:31 - 2018-04-08 13:39 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\PlaceholderTileLogoFolder
2018-07-19 16:31 - 2018-04-08 13:20 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\Packages
2018-07-19 16:14 - 2018-04-08 13:27 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-07-19 16:14 - 2018-04-08 13:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-07-17 16:42 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-07-16 20:40 - 2018-04-08 15:23 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-07-16 15:08 - 2018-04-08 15:01 - 000000000 ____D C:\Program Files (x86)\Corel
2018-07-13 18:22 - 2018-05-22 04:01 - 000003398 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1958513911-1346653992-1749791109-1001
2018-07-13 18:22 - 2018-05-22 03:57 - 000002403 _____ C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-07-13 18:22 - 2018-04-08 13:22 - 000000000 ___RD C:\Users\Matheus Zanutto\OneDrive
2018-07-13 16:25 - 2018-06-05 19:03 - 000002703 _____ C:\Users\Matheus Zanutto\Desktop\poe things.txt
2018-07-12 05:29 - 2018-06-14 22:10 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Local\D3DSCache
2018-07-12 05:28 - 2018-04-08 13:27 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-07-11 17:40 - 2018-05-22 03:56 - 000330448 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-07-11 17:40 - 2018-04-08 13:20 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-11 17:40 - 2018-04-08 13:20 - 000000000 ___RD C:\Users\Matheus Zanutto\3D Objects
2018-07-11 17:39 - 2018-05-22 03:57 - 000000000 ____D C:\Users\Matheus Zanutto
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-07-11 17:39 - 2018-04-12 13:41 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-07-11 17:39 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-07-10 16:02 - 2018-04-08 15:29 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-07-10 16:01 - 2018-04-08 15:29 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-06-28 22:13 - 2018-04-11 20:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-06-28 22:13 - 2018-04-11 20:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-27 14:18 - 2018-04-09 10:11 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\currency-cop
2018-06-26 14:09 - 2018-04-08 15:15 - 000000000 ____D C:\Users\Matheus Zanutto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-26 13:17 - 2018-04-08 15:30 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-24 04:03 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports

==================== Arquivos na raiz de alguns diretórios =======

2018-04-11 20:34 - 2018-04-11 20:34 - 000059904 ____N (Microsoft Corporation) C:\Program Files (x86)\oijYoXoQIUk.exe
2018-04-11 20:34 - 2018-04-11 20:34 - 000059904 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\hCEC.exe
2018-04-11 20:34 - 2018-04-11 20:34 - 000178688 ____N (Microsoft Corporation) C:\Users\Matheus Zanutto\AppData\Local\fOsZDucgnaEUI.exe
2018-07-19 14:18 - 2018-07-19 14:18 - 000000002 _____ () C:\Users\Matheus Zanutto\AppData\Local\imw.ini

Alguns arquivos em TEMP:
====================
2018-07-12 08:26 - 2018-07-12 08:26 - 000080114 _____ () C:\Users\Matheus Zanutto\AppData\Local\Temp\JNativeHook-3772166911178909660.dll
2018-07-18 00:03 - 2018-07-18 00:03 - 000040448 ____N () C:\Users\Matheus Zanutto\AppData\Local\Temp\proxy_vole1362597998321394276.dll
2018-07-18 00:03 - 2018-07-18 00:03 - 000040448 ____N () C:\Users\Matheus Zanutto\AppData\Local\Temp\proxy_vole4578809522435123710.dll
2018-07-18 00:03 - 2018-07-18 00:03 - 000040448 ____N () C:\Users\Matheus Zanutto\AppData\Local\Temp\proxy_vole6007850103480906827.dll

==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

LastRegBack: 2018-05-22 03:56

==================== Fim de FRST.txt ============================
And this is the additional.log
Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 15.07.2018
Executado por Matheus Zanutto (19-07-2018 17:54:20)
Executando a partir de D:\Downloads
Windows 10 Pro Versão 1803 17134.165 (X64) (2018-05-22 07:01:09)
Modo da Inicialização: Safe Mode (with Networking)
==========================================================


==================== Contas: =============================

Administrador (S-1-5-21-1958513911-1346653992-1749791109-500 - Administrator - Disabled)
Convidado (S-1-5-21-1958513911-1346653992-1749791109-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1958513911-1346653992-1749791109-503 - Limited - Disabled)
Matheus Zanutto (S-1-5-21-1958513911-1346653992-1749791109-1001 - Administrator - Enabled) => C:\Users\Matheus Zanutto
WDAGUtilityAccount (S-1-5-21-1958513911-1346653992-1749791109-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 29.0.0.112 - Adobe Systems Incorporated)
Application Verifier x64 External Package (HKLM\...\{62CB44B2-8007-DBB2-1CBA-5CB7309EB3C3}) (Version: 10.1.17134.12 - Microsoft) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.5.2342 - AVAST Software)
Citra (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\{0e4f00d2-d910-46cc-aed9-3d8453954064}) (Version: 1.0.0 - Citra Team)
Corel Graphics - Windows Shell Extension (HKLM\...\_{3CAAE169-6001-48ED-B2C6-5B6F511552FD}) (Version: 18.0.0.448 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM\...\{3CAAE169-6001-48ED-B2C6-5B6F511552FD}) (Version: 18.0.448 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit Keys (HKLM\...\{C8730B1A-133D-4546-8E21-9EC186341F20}) (Version: 18.0.448 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - BR (x64) (HKLM\...\{67D57366-EFCC-46DA-BB1F-BBE89B377177}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Capture (x64) (HKLM\...\{1253ED86-69FD-4A7B-BDF2-96A522583A88}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Common (x64) (HKLM\...\{72922AB6-F920-4C98-985D-EC90CE0918D4}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Connect (x64) (HKLM\...\{9782A612-03A7-488F-A598-33558163D8F8}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - CS (x64) (HKLM\...\{300DB480-7301-436A-A312-B695B2BC6D71}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - CT (x64) (HKLM\...\{43C4A17D-93D9-41C6-8ACA-370EA390ED2A}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Custom Data (x64) (HKLM\...\{02C85FBD-87D3-4352-BF2E-AFE897CD5559}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - CZ (x64) (HKLM\...\{A67AEE14-0435-4B8C-A367-F5EDE6CAF9F6}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - DE (x64) (HKLM\...\{4AA43BE3-D21B-44D7-B9CD-86692DEF3706}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Draw (x64) (HKLM\...\{A66E09BB-9892-421D-9EB9-311D12AA5244}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - EN (x64) (HKLM\...\{A0845CAD-ED13-46A4-A050-5ACE4631FDEC}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - ES (x64) (HKLM\...\{B1452C41-DC90-4B58-8320-ABB515E87FFB}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Filters (x64) (HKLM\...\{6E6D1438-33CC-413B-BC96-3497B1271CDD}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Font Manager (x64) (HKLM\...\{5FB5FF89-0938-49D9-850B-53B78B84A7E4}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - FR (x64) (HKLM\...\{0A182180-3BAF-4B94-BFD0-CF082CC5FF0D}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - IPM (x64) (HKLM\...\{A040C72A-0ADC-4FB9-9DB4-19B18F6053F1}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - IPM Content (x64) (HKLM\...\{FB081BA0-08D2-4C8C-9E55-788A90430BE3}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - IT (x64) (HKLM\...\{8285FEBA-D373-493F-BC78-934F84A0A298}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - JP (x64) (HKLM\...\{F5A1D3E4-416E-4723-AD35-86A372B99174}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - NL (x64) (HKLM\...\{A7922CC8-0EBD-497B-B381-5B3992905327}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - PHOTO-PAINT (x64) (HKLM\...\{04D8C47E-C0FE-4CA5-8878-91ECD9552109}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - PL (x64) (HKLM\...\{6F03D92C-48DB-4182-8A51-BEF8FE64B72C}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Redist (x64) (HKLM\...\{50D1BD2D-6D8C-45A8-9DB5-CDAB7227DB36}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - RU (x64) (HKLM\...\{B83D220A-33AB-4AF5-963A-887BD971270E}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Setup Files (x64) (HKLM\...\{4B3FC55D-E999-4BEC-AF29-1091E574961F}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - VBA (x64) (HKLM\...\{48DD8181-A983-447B-9660-A55A935CA751}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - VideoBrowser (x64) (HKLM\...\{81EBD8D4-9142-4D33-BF34-D99EFC1180F5}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Workspaces (x64) (HKLM\...\{1D4B870D-A5A8-4B88-9520-ED8EFD545AA1}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 - Writing Tools (x64) (HKLM\...\{23A2ABD8-8231-48AD-AD71-FF0566A7DD8F}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 (64-Bit) (HKLM\...\_{4B3FC55D-E999-4BEC-AF29-1091E574961F}) (Version: 18.0.0.448 - Corel Corporation)
CorelDRAW Graphics Suite X8 (HKLM\...\{ECFAF1D6-342D-4AE2-B6BF-82B22F9FE8DE}) (Version: 18.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X8 -TR (x64) (HKLM\...\{ACC8C1B0-E560-4B42-AA52-9CAD14883B29}) (Version: 18.0 - Corel Corporation) Hidden
CurrencyCop 2.0.0-beta.12 (only current user) (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\ad9b865c-58dc-5b28-b27d-6ee8d988422e) (Version: 2.0.0-beta.12 - Nijiko Yonskai)
Dark Souls 3 (HKLM-x32\...\Dark Souls 3_is1) (Version: - )
Dauntless (HKLM\...\{03AFDFA7-7A23-41B1-AAC2-3898591127D3}) (Version: 1.00.0000 - Phoenix Labs)
DiagnosticsHub_CollectionService (HKLM\...\{0CB7B447-4937-4945-B8C0-807A77B830D5}) (Version: 15.7.27520 - Microsoft Corporation) Hidden
Discord (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\Discord) (Version: 0.0.301 - Discord Inc.)
Estudo de aprimoramento de produto para HP Deskjet 1510 series (HKLM\...\{4BAE2611-A06F-4204-AFEC-EF04BF48013E}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\_{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation)
Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation) Hidden
GIGABYTE OC_GURU II (HKLM-x32\...\{5588D686-D23B-4C9D-BDFA-2A7875CD3722}) (Version: 1.56.0000 - GIGABYTE Technology Co.,Ltd.) Hidden
GIGABYTE OC_GURU II (HKLM-x32\...\InstallShield_{5588D686-D23B-4C9D-BDFA-2A7875CD3722}) (Version: 1.56.0000 - GIGABYTE Technology Co.,Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
HP Deskjet 1510 series Ajuda (HKLM-x32\...\{6DFDA448-D4A1-49DB-9217-1501D24861F5}) (Version: 30.0.0 - Hewlett Packard)
HP Deskjet 1510 series Software básico do dispositivo (HKLM\...\{06FD25AF-70F0-4CA9-88EA-490799567F11}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
icecap_collection_neutral (HKLM-x32\...\{12C1EC05-F936-4A80-821E-7AAC64C4E6FF}) (Version: 15.6.27413 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{C8E22DF4-5498-4B61-93CF-3081BE95A1BA}) (Version: 15.6.27413 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{FA83FF72-A39F-487F-9FD5-126C85600DCA}) (Version: 15.6.27406 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{DDDDF8F8-C8B3-4D0E-9679-B96EA592AD75}) (Version: 15.6.27406 - Microsoft Corporation) Hidden
Intel® C++ Redistributables for Windows* on Intel® 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel® Network Connections 23.1.100.0 (HKLM\...\PROSetDX) (Version: 23.1.100.0 - Intel)
IPM_Common_x64 (HKLM\...\{B8C05FFE-C36F-4F17-AD20-739E4BC65AC9}) (Version: 2.9.389 - Your Company Name) Hidden
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kits Configuration Installer (HKLM-x32\...\{6F502640-B753-C101-FFA5-B38C3FA5B29A}) (Version: 10.1.17134.12 - Microsoft) Hidden
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Microsoft OneDrive (HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation)
Microsoft System CLR Types para SQL Server 2017 (HKLM\...\{7F1387A5-855C-43FB-8214-F544009A2026}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft System CLR Types para SQL Server 2017 (HKLM-x32\...\{009580F9-5D92-4824-A7B5-33DA6593703F}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26405 (HKLM-x32\...\{5b295ba9-ef89-4aeb-8acc-b61adb0b9b5f}) (Version: 14.14.26405.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26405 (HKLM-x32\...\{ec9c2282-a836-48a6-9e41-c2f0bf8d678b}) (Version: 14.14.26405.0 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 1.16.1243.427 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\...\{dd8b09df-3ef8-49f1-bd1a-65278435860b}) (Version: 14.0.23217 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 61.0.1 (x64 pt-BR) (HKLM\...\Mozilla Firefox 61.0.1 (x64 pt-BR)) (Version: 61.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.2 - Mozilla)
MSI Development Tools (HKLM-x32\...\{1E406B46-65F4-91CE-65DA-DB66D5443B68}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Object Builder (HKLM-x32\...\{6180D897-08AA-E86F-07C1-EA8C67B25692}) (Version: 0.4.5 - UNKNOWN) Hidden
Object Builder (HKLM-x32\...\com.mignari.ObjectBuilder) (Version: 0.4.5 - UNKNOWN)
Origin (HKLM-x32\...\Origin) (Version: 10.5.17.52805 - Electronic Arts, Inc.)
Painel de controle da NVIDIA 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.13 - NVIDIA Corporation) Hidden
Path of Building version 1.4.78 (HKLM-x32\...\{72FA9AB7-189F-4BDE-8856-72DEB90C157B}_is1) (Version: 1.4.78 - Openarl)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.18.115 - Nome de sua empresa:)
SDK ARM Additions (HKLM-x32\...\{346B2C02-CC0D-6E09-8B9D-CAA2821473CF}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
SDK ARM Redistributables (HKLM-x32\...\{825784BB-114D-ADB3-B65F-E1EB2A63C3BC}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
SimCity (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.98.0213 - Electronic Arts)
Stardew Valley (HKLM-x32\...\1453375253_is1) (Version: 2.7.0.9 - GOG.com)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.1.3629 - TeamViewer)
Universal CRT Extension SDK (HKLM-x32\...\{18ABFDF6-23D9-87E6-015E-FFE3C7F153D5}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Headers Libraries and Sources (HKLM-x32\...\{0D6B41AF-D117-8944-A059-3F9346A896C5}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Redistributable (HKLM-x32\...\{B6273353-8B54-1F89-1A16-5940925104CE}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Tools x64 (HKLM\...\{BA6F1D53-C3F2-F9D5-80CE-CEF608E36AD3}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal CRT Tools x86 (HKLM-x32\...\{6E43CA0C-046E-4F38-A0A2-3B1BA139B661}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Universal General MIDI DLS Extension SDK (HKLM-x32\...\{775886B8-DEE1-CB20-8A94-FC09FA54ECF6}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
vcpp_crt.redist.clickonce (HKLM-x32\...\{9F1104D8-0720-45EC-8BD6-24F383CDC134}) (Version: 14.14.26405 - Microsoft Corporation) Hidden
Visual Studio Community 2017 (HKLM-x32\...\ce57fe48) (Version: 15.7.27703.2000 - Microsoft Corporation)
VS Immersive Activate Helper (HKLM-x32\...\{10948144-16FC-42B6-8DEA-5AC2428278DF}) (Version: 16.0.94.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{4D42BCAC-81DD-4450-8BDC-7FCC4C975D2F}) (Version: 16.0.94.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{48C2D1FA-9F23-40E1-9F16-6A3CA6A78915}) (Version: 16.0.94.0 - Microsoft Corporation) Hidden
vs_communitymsi (HKLM-x32\...\{5DFEB1ED-29B8-44F0-8615-DE758242B0E2}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{24128E7F-36B8-4865-9A0B-EF7EBCA46F1E}) (Version: 15.0.26621 - Microsoft Corporation) Hidden
vs_devenvmsi (HKLM-x32\...\{BFFA2FFB-1095-4ADD-A352-368806D2412B}) (Version: 15.0.26621 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{B6600254-A9D1-4265-826B-28B0E28C1F37}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{EF15DAFE-8E43-48E6-AE94-CBA196675318}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{8EB2C670-04C2-482D-BACD-B4095E27FD39}) (Version: 15.6.27309 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx64 (HKLM\...\{B11D79C6-332C-47B6-B58C-2F88A4911C7C}) (Version: 15.0.27005 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx86 (HKLM-x32\...\{2497054A-0269-4F45-98AE-F469F89CC45F}) (Version: 15.0.27005 - Microsoft Corporation) Hidden
vs_minshellinteropmsi (HKLM-x32\...\{9B1DD088-CF09-46A1-8B42-18D231B19E39}) (Version: 15.7.27604 - Microsoft Corporation) Hidden
vs_minshellmsi (HKLM-x32\...\{F5BCAD30-D22C-4B08-A581-1EBE3A35C6B1}) (Version: 15.7.27617 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{0E68B234-217C-4534-AB01-3388C5D796F5}) (Version: 15.0.26621 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{1AC6CC3D-7724-4D84-9270-798A2191AB1C}) (Version: 15.0.27005 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WinAppDeploy (HKLM-x32\...\{5AD4A604-B476-1578-2A20-6B02FC6258BE}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
Windows Mobile Connectivity Tools 10.0.15254.0 - Desktop x86 (HKLM-x32\...\{833F02C5-2C39-49F6-BD64-91D351081274}) (Version: 10.1.15254.1 - Microsoft Corporation)
Windows SDK AddOn (HKLM-x32\...\{E77C2F78-6089-48F8-89DF-DDF2850DFFD9}) (Version: 10.1.0.0 - Microsoft Corporation)
Windows Software Development Kit - Windows 10.0.17134.12 (HKLM-x32\...\{5f83ccda-0498-4b97-a298-16a642bf49f2}) (Version: 10.1.17134.12 - Microsoft Corporation)
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
WinRT Intellisense Desktop - en-us (HKLM-x32\...\{389D182F-0ADA-5C7E-FF32-2573A821592C}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{C3776B36-B34E-00E2-3009-95A6F1870B58}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - en-us (HKLM-x32\...\{965D1746-D94A-49B9-2A48-A14914CA3B57}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{84C6B91B-67DA-DDE3-86F1-87A3E307E8C1}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense Mobile - en-us (HKLM-x32\...\{3755CD99-C62E-3312-DDD3-29A4F259270D}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - en-us (HKLM-x32\...\{729DA966-8590-2C1F-2178-16C1D32FD7FD}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{F1C18506-3168-A9D9-E2D9-D23A512A326E}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - en-us (HKLM-x32\...\{4095D263-6A13-78D3-DEDA-AA3452011F6E}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{C3243E23-2EB6-4419-2692-40944923B112}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden
XAMPP (HKLM-x32\...\xampp) (Version: 7.2.5-0 - Bitnami)

==================== Exame Personalizado CLSID (Whitelisted): ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext32.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-19] (AVAST Software)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\Winrar\rarext32.dll [2017-08-11] (Alexander Roshal)

==================== Tarefas Agendadas (Whitelisted) =============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {1FCE018D-F084-4B7E-9E2C-38C35EB0B2E8} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {59B4761D-544C-4074-811F-AD33A7546639} - System32\Tasks\{B8A3717B-7F7A-4623-C344-C5DC638D4455} => C:\Program Files (x86)\oijYoXoQIUk.exe [2018-04-11] (Microsoft Corporation) <==== ATENÇÃO
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {69D49877-D21A-4A6E-888D-270B58E898E8} - System32\Tasks\R@1n-KMS\Windows100Professional => wmic [Argument = path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate]
Task: {7C441F15-B847-4205-BD6A-F77F24CFCC4E} - System32\Tasks\CorelUpdateHelperTaskCore => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2018-06-21] (Corel Corporation)
Task: {8872792C-35DF-47C3-9C5B-F8E5A920317E} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-07-19] (AVAST Software)
Task: {95BA7087-8F82-4144-B5E2-05DFBFF87B1C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-19] (Google Inc.)
Task: {974582BC-21EE-47F0-9A86-7D199C230D3D} - System32\Tasks\{F5007D8A-A700-02EA-1ECF-E738E9566150} => C:\Program Files (x86)\Common Files\hCEC.exe [2018-04-11] (Microsoft Corporation)
Task: {A4238E70-129A-4540-8732-A1F2C67AED32} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {BBA49D3D-BD05-472C-8F0C-AA04F7F161D0} - System32\Tasks\{974F87F5-E009-F0AD-8F98-7D4B120EBEB8} => "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://hqfok.com/cl/?guid=j5bez6jjawjofof9fsxi99z6gy1hwzr6&prid=1&pid=4_1324_0
Task: {C13D2FE9-B920-4FFB-AF1A-5AFD955FB7F1} - System32\Tasks\Product Updater => C:\Program Files (x86)\Free Driver Backup\FFProductUpdater.exe
Task: {DECA6DD1-13E0-48EA-9904-BF4CBCB8EFC3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-19] (Google Inc.)
Task: {FC3B8A5D-2583-498E-BE0A-B0FCB06A5F08} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-07-19] (AVAST Software)

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Atalhos & WMI ========================

(As entradas podem ser listadas para serem restauradas ou removidas.)


==================== Módulos Carregados (Whitelisted) ==============

2018-04-11 20:34 - 2018-04-11 20:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 20:34 - 2018-04-11 20:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 20:34 - 2018-04-11 20:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-07-10 15:59 - 2018-07-06 03:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll

==================== Alternate Data Streams (Whitelisted) =========

==================== Modo de Segurança (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Associação (Whitelisted) ===============

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.)


==================== Internet Explorer confiável/restrito ===============

(Se uma entrada for incluída na fixlist, será removida do Registro.)


==================== Hosts Conteúdo: ===============================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2017-09-29 10:46 - 2017-09-29 10:44 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Outras Áreas ============================

(Atualmente não há nenhuma correção automática para esta seção.)

HKU\S-1-5-21-1958513911-1346653992-1749791109-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: O Suporte não está conectado à internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Firewall do Windows está habilitado.

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==


==================== Regras do Firewall (Whitelisted) ===============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [UDP Query User{BC033C90-AF3F-4F51-A8D2-22BC564A3B66}D:\pxg\testglobal\server\theforgottenserver.exe] => (Allow) D:\pxg\testglobal\server\theforgottenserver.exe
FirewallRules: [TCP Query User{BD21D8E0-EAAC-4E83-951D-026C75453763}D:\pxg\testglobal\server\theforgottenserver.exe] => (Allow) D:\pxg\testglobal\server\theforgottenserver.exe
FirewallRules: [UDP Query User{B813507D-1D37-4D2E-920C-8CD6D05ADA03}D:\pxg\proffision\servidor\servidor.exe] => (Allow) D:\pxg\proffision\servidor\servidor.exe
FirewallRules: [TCP Query User{3D589472-4207-4A66-8784-32E144A113A4}D:\pxg\proffision\servidor\servidor.exe] => (Allow) D:\pxg\proffision\servidor\servidor.exe
FirewallRules: [UDP Query User{F463EB58-BAD5-4BEB-800D-DF5B925E51E9}D:\pxg\novim\server\theforgottenserver.exe] => (Allow) D:\pxg\novim\server\theforgottenserver.exe
FirewallRules: [TCP Query User{FAEEE956-653E-4493-BDB3-5077BEBF83C0}D:\pxg\novim\server\theforgottenserver.exe] => (Allow) D:\pxg\novim\server\theforgottenserver.exe
FirewallRules: [UDP Query User{4AB92810-01E4-4A67-AD50-BCB457887036}D:\pxg\rubyserver-master\therubyserver.exe] => (Allow) D:\pxg\rubyserver-master\therubyserver.exe
FirewallRules: [TCP Query User{1A3B52E2-5131-433E-A7D4-582E8B0A7CDB}D:\pxg\rubyserver-master\therubyserver.exe] => (Allow) D:\pxg\rubyserver-master\therubyserver.exe
FirewallRules: [UDP Query User{EDC72A73-048D-4BCF-B5CA-E2D9ABCCB5EC}D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe] => (Allow) D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe
FirewallRules: [TCP Query User{69406ED4-0F3B-464B-AF82-EE5840F2741F}D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe] => (Allow) D:\pxg\pokecpa\dxp - server-v3\pokealpha.exe
FirewallRules: [UDP Query User{CB5A8E0E-12A4-4154-B6E7-295DBDAF06FC}D:\pxg\server poek pa\pokeserver\theforgottenserver.exe] => (Allow) D:\pxg\server poek pa\pokeserver\theforgottenserver.exe
FirewallRules: [TCP Query User{0E42BDEB-C071-4152-BF28-86CF5E017A77}D:\pxg\server poek pa\pokeserver\theforgottenserver.exe] => (Allow) D:\pxg\server poek pa\pokeserver\theforgottenserver.exe
FirewallRules: [UDP Query User{D3CCE180-4F7D-4539-9990-F06B4F0A6BA5}D:\xampp\mysql\bin\mysqld.exe] => (Allow) D:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{31CEB48D-B4F6-42CE-BBF4-28AFF63B9BF2}D:\xampp\mysql\bin\mysqld.exe] => (Allow) D:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{3A65E21B-8E30-44C4-A75E-EC8ABB22ABE5}D:\xampp\apache\bin\httpd.exe] => (Allow) D:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{7BC98DC9-74F7-43B6-8076-5FE2CB200FA3}D:\xampp\apache\bin\httpd.exe] => (Allow) D:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{B63AC3A2-FC19-4254-B100-C97697DB9CE2}D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe
FirewallRules: [TCP Query User{5C43D0A3-1AF7-410D-9EEB-7FC41255FDED}D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.141\deploy\leagueclient.exe
FirewallRules: [UDP Query User{1EEE87E7-C5D7-436C-8DFD-2AB519F45A8F}D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe] => (Allow) D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe
FirewallRules: [TCP Query User{6CFEA1CB-BFD8-4DD8-A5F9-F56D7494DDFE}D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe] => (Allow) D:\pxg\servidor pokemon anonymous 3.1\servidor pokemon anonymous 3.0\po dash world [advanced] - gui.exe
FirewallRules: [{363BCEFC-8095-40B2-AD94-3BBDF9BA794F}] => (Allow) C:\Users\Matheus Zanutto\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E4541927-6693-4CB4-9AD9-AB451A51A6CF}] => (Allow) C:\Users\Matheus Zanutto\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D6003D07-051C-4A2D-B56B-9ED9897E1593}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{2539443C-9A6D-41FD-960F-E0D4941F4B57}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{B2011AD2-30BA-42C7-AEBA-3BA07E13CFEE}] => (Allow) D:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{559AF488-FC48-4079-B0C8-9F8DC508802C}] => (Allow) D:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [UDP Query User{F1C44D2A-9269-48D5-BCAB-9F3866D9626A}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{1CDDB99D-344C-48D5-8E61-7A1D63A6F4C7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{BE2EE86E-CB6C-44D3-9A8C-FA47F639DA91}] => (Allow) C:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE68BCCD-1AAB-4CA9-9799-AA193E782DD5}] => (Allow) C:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{33736E1D-06E8-496D-89D2-1AF5ECC84D29}] => (Allow) C:\SteamLibrary\steamapps\common\Path of Exile\PathOfExileSteam.exe
FirewallRules: [{EDE789AB-E466-4162-9ADE-4D941360B013}] => (Allow) C:\SteamLibrary\steamapps\common\Path of Exile\PathOfExileSteam.exe
FirewallRules: [{BBED1A47-25B4-43A4-8691-DB3D2AD73B56}] => (Block) D:\CorelDRAW Graphics Suite X8\Programs64\CdrConv.exe
FirewallRules: [{D38ED28E-4AB8-4C02-B507-D5A5FEAD3B3A}] => (Block) D:\CorelDRAW Graphics Suite X8\Programs64\CorelPP.exe
FirewallRules: [{B07D321B-81B8-4B40-81CB-0B6371717DB0}] => (Block) D:\CorelDRAW Graphics Suite X8\Programs64\CorelDRW.exe
FirewallRules: [{EF94DD69-16B5-42A4-80F7-F348AE0B5D70}] => (Block) d:\CorelDRAW Graphics Suite X8\Programs64\CorelPP.exe
FirewallRules: [{0734B79D-2908-4ACC-8BA2-1BB69ABA361F}] => (Block) d:\CorelDRAW Graphics Suite X8\Programs64\CorelDrw.exe
FirewallRules: [{4C89A848-F602-499C-8C32-13F5F9FC54D0}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F6D0CB2A-2F8B-4CEB-B618-4A077AA88E7F}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{595C5865-053C-455F-9BE9-93A9CF64C540}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{331A2530-B1DF-469D-AB0B-127BBD801BB9}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{A5D4487E-612D-4ABA-9608-1CEFF077E98F}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{232D5C0D-06B2-46E9-97C8-AEF9C3855DD8}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{C4D4C7C7-5317-4BBB-8F78-159156A59E3B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{F15B01F2-4FA8-46D2-B1A2-87472255D342}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{ABC9A59C-B25E-43F0-907E-E71AE7128213}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{B0BFBAB2-1235-42FC-A07B-767248E61410}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{F33DB86F-0046-46B4-A88F-15D5FF5FAE28}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{F556E6A5-FAF2-45FC-86E9-D47543EDBCBC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{68E1F4F5-7726-4F4F-A953-5030669354F6}] => (Allow) D:\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe
FirewallRules: [{1CDED122-F1DA-4EB0-B743-C3F6665145FD}] => (Allow) D:\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe
FirewallRules: [TCP Query User{67D75185-E223-4002-A9D7-BDE786AA93DB}D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe
FirewallRules: [UDP Query User{1E791C73-62D4-4B36-9F62-A9BD74A4587D}D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.153\deploy\leagueclient.exe
FirewallRules: [{6047D139-E12B-4E93-9A65-556539A34B76}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{66241F6E-8056-41C3-8039-468EACD57034}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{0291AE34-15CC-4BAB-8146-1578131B85D7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{94AF8459-6E8D-46F6-ACC5-54C3D632DCD4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{AD6F31A9-32C1-4FC6-B595-B7EC808A3EBA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{D9598AB7-0FBA-4BC6-A7A0-32803EEA2392}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{C45BD4E7-F9D5-464D-9778-0989438BCE10}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{D3DE5333-B930-4E92-8C23-5603C6CF12BC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{52BA74CF-53C6-453C-8230-058E8E27D53D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
FirewallRules: [{16611E6B-9D88-46F6-AD16-2890A49F81CE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.85.257.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
FirewallRules: [TCP Query User{1F6E5984-16AB-4991-8723-0047591177FC}D:\jdownloader\jdownloader v2.0\jdownloader2.exe] => (Allow) D:\jdownloader\jdownloader v2.0\jdownloader2.exe
FirewallRules: [UDP Query User{A94F5F23-F789-48C0-AE2D-BDFD5E1DD3D3}D:\jdownloader\jdownloader v2.0\jdownloader2.exe] => (Allow) D:\jdownloader\jdownloader v2.0\jdownloader2.exe
FirewallRules: [TCP Query User{7902AD59-6AAF-4269-BD22-48F5BB811AB5}D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe
FirewallRules: [UDP Query User{2420BE31-D32A-4273-9FD8-6B9C0641FF9F}D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) D:\lol\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe
FirewallRules: [{4169313C-0763-43CE-A4E0-CDF8983B24E9}] => (Allow) C:\WINDOWS\SysWOW64\msiexec.exe
FirewallRules: [{045BEA7E-EC86-4C3E-B48C-E8440FFF7CCE}] => (Allow) C:\Program Files (x86)\oijYoXoQIUk.exe
FirewallRules: [{A363F146-6458-4E55-84CF-81381EC73E9E}] => (Allow) C:\Program Files (x86)\Common Files\hCEC.exe
FirewallRules: [{FAD1770A-0D6B-44DC-A9E0-7C8E23FB9330}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{EA0ACB89-93A0-4FEA-8BBF-963112CE4333}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{26EF3551-CD14-48B5-83D8-74B7B2BFDE16}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{41A23472-4432-435A-BD49-453BD26B3C34}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{DEE8E28B-9960-4150-ABD4-2BE6332ACB8A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E346A14D-E64D-4EE8-9E97-CF61400D8ECB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{9DC1E53E-264E-4E6D-9B73-EF8E6734AA92}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{4AE125DE-46A8-4C1E-8081-24A54E3F496D}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{F0C45DFE-B37B-43BE-968E-004EBA1E099A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{565B8AB7-B7D5-4E57-8A1F-08378DF11651}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{9250ACA9-FFD6-4D94-BDB3-92FEAA2EB220}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{D9FD64EA-2687-43D2-9011-44B43724F25D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{C3D7A33F-94E3-43BF-BB08-EC371F669A51}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe

==================== Pontos de Restauração =========================

ATENÇÃO: A Restauração do Sistema está desabilitada

==================== Dispositivos Apresentando Falhas No Gerenciador =============

Name: NVIDIA High Definition Audio
Description: NVIDIA High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: NVHDA
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Erros no Log de eventos: =========================

Erros em Aplicativos:
==================
Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:51:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:46:58 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.

Error: (07/19/2018 05:39:32 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\MFC80U.DLL".
Assembly dependente Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" não pôde ser localizado.
Use o arquivo sxstrace.exe para obter um diagnóstico detalhado.


Erros de Sistema:
=============
Error: (07/19/2018 05:54:21 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:54:05 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:53 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:40 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:35 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/19/2018 05:53:32 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço TokenBroker com argumentos "Não Disponível" para executar o servidor:
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal

Error: (07/19/2018 05:53:31 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço WSearch com argumentos "Não Disponível" para executar o servidor:
{E48EDA45-43C6-48E0-9323-A7B2067D9CD5}

Error: (07/19/2018 05:53:27 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-Q3D5SVE)
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço ShellHWDetection com argumentos "Não Disponível" para executar o servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}


Windows Defender:
===================================
Date: 2018-07-19 16:11:06.932
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Zpevdo.A&threatid=2147727143&enterprise=0
Nome: Trojan:Win32/Zpevdo.A
ID: 2147727143
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\Desktop\jailbreak-exploit_11.4.1-3\exploit_v3.exe
Origem da Detecção: Computador local
Tipo de Detecção: FastPath
Origem da Detecção: Sistema
Usuário: AUTORIDADE NT\SISTEMA
Nome do Processo: C:\Windows\System32\consent.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 16:11:03.243
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Zpevdo.A&threatid=2147727143&enterprise=0
Nome: Trojan:Win32/Zpevdo.A
ID: 2147727143
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\Desktop\jailbreak-exploit_11.4.1-3\exploit_v3.exe
Origem da Detecção: Computador local
Tipo de Detecção: FastPath
Origem da Detecção: Sistema
Usuário: AUTORIDADE NT\SISTEMA
Nome do Processo: Unknown
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 14:20:59.775
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Brocoiner!rfn&threatid=2147724297&enterprise=0
Nome: Trojan:HTML/Brocoiner!rfn
ID: 2147724297
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\AppData\Local\Mozilla\Firefox\Profiles\214l4ozi.default\cache2\entries\CE94BF5164C04AE312403C4CA6A85F4F3B1133A2
Origem da Detecção: Computador local
Tipo de Detecção: Concreto
Origem da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-Q3D5SVE\Matheus Zanutto
Nome do Processo: C:\Program Files\Mozilla Firefox\firefox.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 14:20:41.034
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Brocoiner!rfn&threatid=2147724297&enterprise=0
Nome: Trojan:HTML/Brocoiner!rfn
ID: 2147724297
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\AppData\Local\Mozilla\Firefox\Profiles\214l4ozi.default\cache2\entries\CE94BF5164C04AE312403C4CA6A85F4F3B1133A2
Origem da Detecção: Computador local
Tipo de Detecção: Concreto
Origem da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-Q3D5SVE\Matheus Zanutto
Nome do Processo: C:\Program Files\Mozilla Firefox\firefox.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-07-19 14:20:32.021
Description:
O Windows Defender Antivirus detectou malware ou outros softwares potencialmente indesejados.
Para obter mais informações, consulte:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Brocoiner!rfn&threatid=2147724297&enterprise=0
Nome: Trojan:HTML/Brocoiner!rfn
ID: 2147724297
Severidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Matheus Zanutto\AppData\Local\Mozilla\Firefox\Profiles\214l4ozi.default\cache2\entries\CE94BF5164C04AE312403C4CA6A85F4F3B1133A2
Origem da Detecção: Computador local
Tipo de Detecção: Concreto
Origem da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-Q3D5SVE\Matheus Zanutto
Nome do Processo: C:\Program Files\Mozilla Firefox\firefox.exe
Versão da Assinatura: AV: 1.273.20.0, AS: 1.273.20.0, NIS: 1.273.20.0
Versão do Mecanismo: AM: 1.1.15100.1, NIS: 1.1.15100.1

==================== Informações da Memória ===========================

Processador: Intel® Core™ i7-3770 CPU @ 3.40GHz
Percentagem de memória em uso: 8%
RAM física total: 12266.4 MB
RAM física disponível: 11182.75 MB
Virtual Total: 16362.4 MB
Virtual disponível: 15498.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.22 GB) (Free:41.91 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:688.37 GB) NTFS

\\?\Volume{fa16dff0-0000-0000-0000-100000000000}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
\\?\Volume{fa16dff0-0000-0000-0000-30d41b000000}\ () (Fixed) (Total:0.47 GB) (Free:0.08 GB) NTFS

==================== MBR & Tabela de Partições ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: FA16DFF0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=484 MB) - (Type=27)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 360A2C64)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== Fim de Addition.txt ============================
Ps: I can only run the FRST in security mode

#4 britechguy

britechguy

    Been there, done that, got the T-shirt


  • Moderator
  • 8,154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Staunton, VA
  • Local time:06:10 PM

Posted 19 July 2018 - 08:50 PM

Member reports issue has been solved.


Brian  AKA  Bri the Tech Guy (website in my user profile) - Windows 10 Home, 64-Bit, Version 1803, Build 17134 

      Memory is a crazy woman that hoards rags and throws away food.

                    ~ Austin O'Malley

 

 

 

              

 





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users