Lorddiablos
Posts: 14 +0
Here's the log
Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 17.03.2019
Executado por User (administrador) em USER-PC (25-03-2019 14:04:35)
Executando a partir de C:\Users\User\Downloads
Perfis Carregados: User (Perfis Disponíveis: User)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processos (Whitelisted) =================
(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registro (Whitelisted) ===========================
(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\...\Drivers32: [msacm.ac3filter] => C:\Windows\SysWOW64\ac3filter.acm [1679360 2013-04-05] () [Arquivo não assinado]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-25] (Google LLC -> Google Inc.)
==================== Internet (Whitelisted) ====================
(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{BC9C118A-85F4-42E8-A362-6AA98F08A6ED}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Internet Explorer:
==================
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-03-21] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-03-21] (Google Inc -> Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2019-03-25]
CHR Extension: (Apresentações) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-25]
CHR Extension: (Documentos) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-03-25]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-03-25]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-25]
CHR Extension: (Planilhas) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-25]
CHR Extension: (Documentos Google off-line) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-03-25]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-03-25]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-03-25]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-25]
CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Serviços (Whitelisted) ====================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2019-03-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [127136 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73912 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [274416 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [104784 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Microsoft Windows -> Realtek Semiconductor Corporation )
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [28272 2019-03-25] (Adlice -> )
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
==================== Um mês (criados) ========
(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)
2019-03-25 14:04 - 2019-03-25 14:06 - 000008509 _____ C:\Users\User\Downloads\FRST.txt
2019-03-25 13:57 - 2019-03-25 14:04 - 000000000 ____D C:\FRST
2019-03-25 02:43 - 2019-03-25 02:43 - 000028272 _____ C:\Windows\system32\Drivers\truesight.sys
2019-03-25 02:41 - 2019-03-25 02:41 - 000073912 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-03-25 02:40 - 2019-03-25 02:40 - 000274416 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-03-25 02:40 - 2019-03-25 02:40 - 000127136 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-03-25 02:40 - 2019-03-25 02:40 - 000104784 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-03-25 02:04 - 2019-03-25 02:04 - 000000000 ____D C:\Windows\system32\SPReview
2019-03-25 02:03 - 2019-03-25 02:03 - 000000000 ____D C:\Windows\system32\EventProviders
2019-03-25 02:01 - 2010-11-20 10:27 - 008988160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-03-25 02:01 - 2010-11-04 22:57 - 001942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2019-03-25 02:01 - 2010-11-04 22:57 - 000048976 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2019-03-25 02:00 - 2010-11-20 10:39 - 005066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2019-03-25 02:00 - 2010-11-20 10:33 - 001924480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-03-25 02:00 - 2010-11-20 10:33 - 001659776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-03-25 02:00 - 2010-11-20 10:33 - 000951680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2019-03-25 02:00 - 2010-11-20 10:33 - 000299392 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2019-03-25 02:00 - 2010-11-20 10:33 - 000273792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2019-03-25 02:00 - 2010-11-20 10:28 - 001731936 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 014633472 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 014174208 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003860992 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003715584 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003650560 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003027968 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2019-03-25 02:00 - 2010-11-20 10:27 - 003008000 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002314752 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002086912 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002018304 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001888256 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2019-03-25 02:00 - 2010-11-20 10:27 - 001881088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001753088 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001646080 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001556992 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001490944 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001465344 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001326080 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001219584 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001197056 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001188864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001109504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001026560 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000960512 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000867840 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000849920 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000750080 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000263168 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\tssrvlic.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 012260864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 004120064 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 003391488 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 003205120 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 002565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 002444288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 002067456 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001866240 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001838080 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001340416 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001137664 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000919040 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000853504 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2019-03-25 02:00 - 2010-11-20 10:26 - 000828416 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000784896 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000777728 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000715264 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 003957760 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 001975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 001600512 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 001456128 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000958464 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000902144 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000598016 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000359424 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000301568 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000095744 _____ C:\Windows\system32\RDVGHelper.exe
2019-03-25 02:00 - 2010-11-20 10:24 - 002872320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2019-03-25 02:00 - 2010-11-20 09:32 - 005066752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthFWSnapin.dll
2019-03-25 02:00 - 2010-11-20 09:30 - 000079232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvgumd32.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 012872192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 011410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 001548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 001229824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 001115136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 000980992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 000870912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 000423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2019-03-25 02:00 - 2010-11-20 09:20 - 001414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-03-25 02:00 - 2010-11-20 09:20 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 010990080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 005977600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 003215872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 003207680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 002064384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 001698816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 001493504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 000954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 000954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2019-03-25 02:00 - 2010-11-20 09:18 - 001334272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2019-03-25 02:00 - 2010-11-20 09:18 - 001171456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2019-03-25 02:00 - 2010-11-20 09:18 - 000739840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2019-03-25 02:00 - 2010-11-20 09:17 - 000327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2019-03-25 02:00 - 2010-11-20 09:17 - 000322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2019-03-25 02:00 - 2010-11-20 09:17 - 000051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PushPrinterConnections.exe
2019-03-25 02:00 - 2010-11-20 08:07 - 000162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2019-03-25 02:00 - 2010-11-20 08:07 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2019-03-25 02:00 - 2010-11-20 08:05 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2019-03-25 02:00 - 2010-11-20 06:53 - 003126272 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-03-25 02:00 - 2010-11-20 06:28 - 000468992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-03-25 02:00 - 2010-11-20 06:27 - 000413184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-03-25 02:00 - 2010-11-20 06:25 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2019-03-25 02:00 - 2010-11-20 06:23 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2019-03-25 02:00 - 2010-11-04 23:20 - 000347904 _____ C:\Windows\system32\systemsf.ebd
2019-03-25 02:00 - 2010-11-04 22:58 - 001130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2019-03-25 02:00 - 2010-11-04 22:58 - 000297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2019-03-25 02:00 - 2010-11-04 22:57 - 000444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2019-03-25 02:00 - 2010-11-04 22:53 - 000320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2019-03-25 02:00 - 2010-11-04 22:53 - 000295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2019-03-25 02:00 - 2010-11-04 22:53 - 000109928 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2019-03-25 02:00 - 2010-11-04 22:53 - 000099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2019-03-25 02:00 - 2009-07-13 22:16 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pmcsnap.dll
2019-03-25 02:00 - 2009-07-13 22:16 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ppcsnap.dll
2019-03-25 01:59 - 2010-11-20 10:34 - 000295808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2019-03-25 01:59 - 2010-11-20 10:34 - 000215936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2019-03-25 01:59 - 2010-11-20 10:34 - 000199552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbus.sys
2019-03-25 01:59 - 2010-11-20 10:34 - 000071552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000982912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-03-25 01:59 - 2010-11-20 10:33 - 000376192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000366976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000289664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000263040 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-03-25 01:59 - 2010-11-20 10:33 - 000189824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000184704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000140672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000095616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000078720 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\HpSAMD.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000075136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000063360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000031104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2019-03-25 01:59 - 2010-11-20 10:32 - 000334208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2019-03-25 01:59 - 2010-11-20 10:32 - 000179072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 17.03.2019
Executado por User (administrador) em USER-PC (25-03-2019 14:04:35)
Executando a partir de C:\Users\User\Downloads
Perfis Carregados: User (Perfis Disponíveis: User)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processos (Whitelisted) =================
(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registro (Whitelisted) ===========================
(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\...\Drivers32: [msacm.ac3filter] => C:\Windows\SysWOW64\ac3filter.acm [1679360 2013-04-05] () [Arquivo não assinado]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-25] (Google LLC -> Google Inc.)
==================== Internet (Whitelisted) ====================
(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{BC9C118A-85F4-42E8-A362-6AA98F08A6ED}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Internet Explorer:
==================
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-03-21] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-03-21] (Google Inc -> Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2019-03-25]
CHR Extension: (Apresentações) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-25]
CHR Extension: (Documentos) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-03-25]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-03-25]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-25]
CHR Extension: (Planilhas) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-25]
CHR Extension: (Documentos Google off-line) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-03-25]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-03-25]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-03-25]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-25]
CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Serviços (Whitelisted) ====================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2019-03-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [127136 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73912 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [274416 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [104784 2019-03-25] (Malwarebytes Corporation -> Malwarebytes)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Microsoft Windows -> Realtek Semiconductor Corporation )
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [28272 2019-03-25] (Adlice -> )
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
==================== Um mês (criados) ========
(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)
2019-03-25 14:04 - 2019-03-25 14:06 - 000008509 _____ C:\Users\User\Downloads\FRST.txt
2019-03-25 13:57 - 2019-03-25 14:04 - 000000000 ____D C:\FRST
2019-03-25 02:43 - 2019-03-25 02:43 - 000028272 _____ C:\Windows\system32\Drivers\truesight.sys
2019-03-25 02:41 - 2019-03-25 02:41 - 000073912 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-03-25 02:40 - 2019-03-25 02:40 - 000274416 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-03-25 02:40 - 2019-03-25 02:40 - 000127136 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-03-25 02:40 - 2019-03-25 02:40 - 000104784 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-03-25 02:04 - 2019-03-25 02:04 - 000000000 ____D C:\Windows\system32\SPReview
2019-03-25 02:03 - 2019-03-25 02:03 - 000000000 ____D C:\Windows\system32\EventProviders
2019-03-25 02:01 - 2010-11-20 10:27 - 008988160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-03-25 02:01 - 2010-11-04 22:57 - 001942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2019-03-25 02:01 - 2010-11-04 22:57 - 000048976 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2019-03-25 02:00 - 2010-11-20 10:39 - 005066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2019-03-25 02:00 - 2010-11-20 10:33 - 001924480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-03-25 02:00 - 2010-11-20 10:33 - 001659776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-03-25 02:00 - 2010-11-20 10:33 - 000951680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2019-03-25 02:00 - 2010-11-20 10:33 - 000299392 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2019-03-25 02:00 - 2010-11-20 10:33 - 000273792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2019-03-25 02:00 - 2010-11-20 10:28 - 001731936 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 014633472 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 014174208 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003860992 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003715584 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003650560 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 003027968 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2019-03-25 02:00 - 2010-11-20 10:27 - 003008000 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002314752 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002086912 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002018304 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001888256 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2019-03-25 02:00 - 2010-11-20 10:27 - 001881088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001753088 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001646080 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001556992 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001490944 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001465344 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001326080 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001219584 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001197056 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001188864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001109504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 001026560 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000960512 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000867840 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000849920 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000750080 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000263168 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\tssrvlic.dll
2019-03-25 02:00 - 2010-11-20 10:27 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 012260864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 004120064 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 003391488 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 003205120 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 002565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 002444288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 002067456 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001866240 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001838080 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001340416 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 001137664 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000919040 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000853504 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2019-03-25 02:00 - 2010-11-20 10:26 - 000828416 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000784896 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000777728 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000715264 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-03-25 02:00 - 2010-11-20 10:26 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 003957760 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 001975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 001600512 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 001456128 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000958464 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000902144 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-03-25 02:00 - 2010-11-20 10:25 - 000598016 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000359424 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000301568 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2019-03-25 02:00 - 2010-11-20 10:25 - 000095744 _____ C:\Windows\system32\RDVGHelper.exe
2019-03-25 02:00 - 2010-11-20 10:24 - 002872320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2019-03-25 02:00 - 2010-11-20 09:32 - 005066752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthFWSnapin.dll
2019-03-25 02:00 - 2010-11-20 09:30 - 000079232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvgumd32.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 012872192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 011410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 001548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 001229824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 001115136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 000980992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 000870912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2019-03-25 02:00 - 2010-11-20 09:21 - 000423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2019-03-25 02:00 - 2010-11-20 09:20 - 001414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-03-25 02:00 - 2010-11-20 09:20 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 010990080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 005977600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 003215872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 003207680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 002064384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 001698816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 001493504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 000954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2019-03-25 02:00 - 2010-11-20 09:19 - 000954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2019-03-25 02:00 - 2010-11-20 09:18 - 001334272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2019-03-25 02:00 - 2010-11-20 09:18 - 001171456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2019-03-25 02:00 - 2010-11-20 09:18 - 000739840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2019-03-25 02:00 - 2010-11-20 09:17 - 000327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2019-03-25 02:00 - 2010-11-20 09:17 - 000322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2019-03-25 02:00 - 2010-11-20 09:17 - 000051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PushPrinterConnections.exe
2019-03-25 02:00 - 2010-11-20 08:07 - 000162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2019-03-25 02:00 - 2010-11-20 08:07 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2019-03-25 02:00 - 2010-11-20 08:05 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2019-03-25 02:00 - 2010-11-20 06:53 - 003126272 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-03-25 02:00 - 2010-11-20 06:28 - 000468992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-03-25 02:00 - 2010-11-20 06:27 - 000413184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-03-25 02:00 - 2010-11-20 06:25 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2019-03-25 02:00 - 2010-11-20 06:23 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2019-03-25 02:00 - 2010-11-04 23:20 - 000347904 _____ C:\Windows\system32\systemsf.ebd
2019-03-25 02:00 - 2010-11-04 22:58 - 001130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2019-03-25 02:00 - 2010-11-04 22:58 - 000297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2019-03-25 02:00 - 2010-11-04 22:57 - 000444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2019-03-25 02:00 - 2010-11-04 22:53 - 000320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2019-03-25 02:00 - 2010-11-04 22:53 - 000295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2019-03-25 02:00 - 2010-11-04 22:53 - 000109928 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2019-03-25 02:00 - 2010-11-04 22:53 - 000099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2019-03-25 02:00 - 2009-07-13 22:16 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pmcsnap.dll
2019-03-25 02:00 - 2009-07-13 22:16 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ppcsnap.dll
2019-03-25 01:59 - 2010-11-20 10:34 - 000295808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2019-03-25 01:59 - 2010-11-20 10:34 - 000215936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2019-03-25 01:59 - 2010-11-20 10:34 - 000199552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbus.sys
2019-03-25 01:59 - 2010-11-20 10:34 - 000071552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000982912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-03-25 01:59 - 2010-11-20 10:33 - 000376192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000366976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000289664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000263040 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-03-25 01:59 - 2010-11-20 10:33 - 000189824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000184704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000140672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000095616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000078720 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\HpSAMD.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000075136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000063360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2019-03-25 01:59 - 2010-11-20 10:33 - 000031104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2019-03-25 01:59 - 2010-11-20 10:32 - 000334208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2019-03-25 01:59 - 2010-11-20 10:32 - 000179072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys