Advertisement
Guest User

Untitled

a guest
Dec 3rd, 2015
99
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 99.15 KB | None | 0 0
  1. OTL logfile created on: 03/12/2015 22:55:29 - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Gabriel\Downloads
  3. 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.11.9600.18098)
  5. Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
  6.  
  7. 6,00 Gb Total Physical Memory | 4,45 Gb Available Physical Memory | 74,10% Memory free
  8. 12,00 Gb Paging File | 10,31 Gb Available in Paging File | 85,95% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 465,76 Gb Total Space | 253,73 Gb Free Space | 54,48% Space Free | Partition Type: NTFS
  13. Drive D: | 74,56 Gb Total Space | 74,46 Gb Free Space | 99,87% Space Free | Partition Type: NTFS
  14.  
  15. Computer Name: GABRIEL-PC | User Name: Gabriel | Logged in as Administrator.
  16. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
  17. Company Name Whitelist: On | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  18.  
  19. [color=#E56717]========== Processes (SafeList) ==========[/color]
  20.  
  21. PRC - [2015/12/03 22:52:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Gabriel\Downloads\OTL.exe
  22. PRC - [2015/11/30 08:50:42 | 006,887,696 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  23. PRC - [2014/03/17 04:36:55 | 000,795,672 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe
  24. PRC - [2012/02/13 22:19:20 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe
  25.  
  26.  
  27. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  28.  
  29. MOD - [2014/03/17 04:38:34 | 000,866,056 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerDVD14\common\UNO\UNO.dll
  30. MOD - [2014/03/17 04:38:03 | 000,043,784 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerDVD14\Kernel\DHProcedure\DHProcedure.dll
  31. MOD - [2013/12/10 05:39:42 | 000,721,920 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerDVD14\Common\Koan\_ssl.pyd
  32. MOD - [2013/12/10 05:39:42 | 000,285,184 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerDVD14\Common\Koan\_hashlib.pyd
  33. MOD - [2013/12/10 05:39:42 | 000,074,240 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerDVD14\Common\Koan\_ctypes.pyd
  34. MOD - [2013/12/10 05:39:42 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\CyberLink\PowerDVD14\Common\Koan\_socket.pyd
  35.  
  36.  
  37. [color=#E56717]========== Services (SafeList) ==========[/color]
  38.  
  39. SRV:[b]64bit:[/b] - [2015/07/22 11:52:08 | 001,633,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
  40. SRV:[b]64bit:[/b] - [2015/07/16 16:58:34 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
  41. SRV:[b]64bit:[/b] - [2015/05/30 17:36:24 | 000,230,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
  42. SRV:[b]64bit:[/b] - [2015/05/12 11:19:37 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
  43. SRV:[b]64bit:[/b] - [2015/05/07 13:21:51 | 000,522,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
  44. SRV:[b]64bit:[/b] - [2015/02/20 21:49:18 | 000,780,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
  45. SRV:[b]64bit:[/b] - [2014/10/31 02:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
  46. SRV:[b]64bit:[/b] - [2014/10/29 02:09:06 | 000,092,992 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
  47. SRV:[b]64bit:[/b] - [2014/10/29 01:59:51 | 003,460,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
  48. SRV:[b]64bit:[/b] - [2014/10/29 00:42:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
  49. SRV:[b]64bit:[/b] - [2014/10/29 00:42:03 | 000,041,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
  50. SRV:[b]64bit:[/b] - [2014/10/29 00:34:51 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
  51. SRV:[b]64bit:[/b] - [2014/10/29 00:33:55 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
  52. SRV:[b]64bit:[/b] - [2014/10/29 00:30:35 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
  53. SRV:[b]64bit:[/b] - [2014/10/29 00:29:22 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
  54. SRV:[b]64bit:[/b] - [2014/10/28 23:57:05 | 000,324,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
  55. SRV:[b]64bit:[/b] - [2014/10/28 23:48:20 | 000,166,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
  56. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
  57. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
  58. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
  59. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
  60. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
  61. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
  62. SRV:[b]64bit:[/b] - [2014/10/28 23:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
  63. SRV:[b]64bit:[/b] - [2014/10/28 23:27:21 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
  64. SRV:[b]64bit:[/b] - [2014/10/28 23:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
  65. SRV:[b]64bit:[/b] - [2014/10/28 23:24:37 | 000,131,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
  66. SRV:[b]64bit:[/b] - [2014/10/28 23:22:40 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
  67. SRV:[b]64bit:[/b] - [2014/10/28 23:20:03 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
  68. SRV:[b]64bit:[/b] - [2014/10/28 23:19:20 | 000,550,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
  69. SRV:[b]64bit:[/b] - [2014/10/28 23:16:17 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
  70. SRV:[b]64bit:[/b] - [2014/10/28 23:13:24 | 000,374,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
  71. SRV:[b]64bit:[/b] - [2014/10/28 23:13:02 | 000,260,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
  72. SRV:[b]64bit:[/b] - [2014/10/28 23:12:36 | 000,407,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
  73. SRV:[b]64bit:[/b] - [2014/10/28 23:12:22 | 000,270,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
  74. SRV:[b]64bit:[/b] - [2014/10/28 23:11:10 | 001,639,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
  75. SRV:[b]64bit:[/b] - [2014/10/28 23:05:09 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
  76. SRV:[b]64bit:[/b] - [2014/10/28 22:48:52 | 000,562,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
  77. SRV:[b]64bit:[/b] - [2014/10/28 22:46:48 | 001,348,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
  78. SRV:[b]64bit:[/b] - [2014/10/28 22:35:51 | 001,668,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
  79. SRV:[b]64bit:[/b] - [2013/08/22 10:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
  80. SRV - [2015/11/30 08:50:42 | 006,887,696 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe -- (TeamViewer)
  81. SRV - [2015/11/28 00:44:24 | 000,269,000 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
  82. SRV - [2015/11/17 23:23:28 | 000,169,128 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
  83. SRV - [2015/06/26 09:02:56 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.11.149\McCHSvc.exe -- (McComponentHostService)
  84. SRV - [2015/06/10 10:11:26 | 000,155,520 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
  85. SRV - [2015/05/07 13:05:40 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
  86. SRV - [2014/10/28 23:51:55 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
  87. SRV - [2014/10/28 23:04:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
  88. SRV - [2013/08/22 10:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
  89. SRV - [2012/10/04 13:07:17 | 006,371,192 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Arquivos de Programas\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)
  90. SRV - [2012/02/13 22:19:20 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe -- (BBUpdate)
  91. SRV - [2012/02/13 22:19:20 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe -- (BBSvc)
  92. SRV - [2010/01/09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
  93. SRV - [2010/01/09 22:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose64)
  94. SRV - [2009/06/11 03:59:58 | 000,239,104 | ---- | M] (IDT, Inc.) [Auto | Running] -- c:\Arquivos de Programas\IDT\v114_ECS_D_6207.2V7_6099.8xp_G2.0V_RC_SDC\WDM\stacsv64.exe -- (STacSV)
  95.  
  96.  
  97. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  98.  
  99. DRV:[b]64bit:[/b] - [2015/11/30 23:46:29 | 000,030,848 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\Windows\SysNative\drivers\TrueSight.sys -- (TrueSight)
  100. DRV:[b]64bit:[/b] - [2015/09/29 10:24:42 | 000,155,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
  101. DRV:[b]64bit:[/b] - [2015/04/16 04:17:07 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
  102. DRV:[b]64bit:[/b] - [2015/03/19 23:56:10 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
  103. DRV:[b]64bit:[/b] - [2015/03/17 15:26:06 | 000,467,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
  104. DRV:[b]64bit:[/b] - [2015/03/13 02:03:31 | 000,239,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
  105. DRV:[b]64bit:[/b] - [2015/03/09 00:02:51 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
  106. DRV:[b]64bit:[/b] - [2015/03/09 00:02:45 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsp.sys -- (storvsp)
  107. DRV:[b]64bit:[/b] - [2015/03/04 08:25:11 | 000,377,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
  108. DRV:[b]64bit:[/b] - [2014/11/10 16:06:59 | 000,136,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
  109. DRV:[b]64bit:[/b] - [2014/10/29 01:59:47 | 000,415,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
  110. DRV:[b]64bit:[/b] - [2014/10/29 01:57:42 | 000,054,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
  111. DRV:[b]64bit:[/b] - [2014/10/29 01:56:04 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
  112. DRV:[b]64bit:[/b] - [2014/10/29 00:46:43 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
  113. DRV:[b]64bit:[/b] - [2014/10/29 00:46:09 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
  114. DRV:[b]64bit:[/b] - [2014/10/29 00:45:54 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
  115. DRV:[b]64bit:[/b] - [2014/10/29 00:45:39 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
  116. DRV:[b]64bit:[/b] - [2014/10/29 00:45:16 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
  117. DRV:[b]64bit:[/b] - [2014/10/15 06:32:36 | 000,921,920 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
  118. DRV:[b]64bit:[/b] - [2014/10/13 00:43:17 | 000,086,336 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
  119. DRV:[b]64bit:[/b] - [2014/10/13 00:43:17 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
  120. DRV:[b]64bit:[/b] - [2014/10/07 04:54:45 | 000,189,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
  121. DRV:[b]64bit:[/b] - [2014/10/07 04:44:39 | 000,069,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
  122. DRV:[b]64bit:[/b] - [2014/08/14 22:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
  123. DRV:[b]64bit:[/b] - [2014/03/13 10:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
  124. DRV:[b]64bit:[/b] - [2014/02/22 13:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
  125. DRV:[b]64bit:[/b] - [2014/02/22 10:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
  126. DRV:[b]64bit:[/b] - [2013/10/25 23:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
  127. DRV:[b]64bit:[/b] - [2013/10/05 13:25:54 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
  128. DRV:[b]64bit:[/b] - [2013/09/14 12:06:57 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
  129. DRV:[b]64bit:[/b] - [2013/08/22 20:59:47 | 000,022,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\kbldfltr.sys -- (kbldfltr)
  130. DRV:[b]64bit:[/b] - [2013/08/22 20:59:39 | 000,220,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Vid.sys -- (Vid)
  131. DRV:[b]64bit:[/b] - [2013/08/22 20:59:39 | 000,129,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbusr.sys -- (vmbusr)
  132. DRV:[b]64bit:[/b] - [2013/08/22 20:59:39 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcivsp.sys -- (vpcivsp)
  133. DRV:[b]64bit:[/b] - [2013/08/22 20:59:39 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
  134. DRV:[b]64bit:[/b] - [2013/08/22 11:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
  135. DRV:[b]64bit:[/b] - [2013/08/22 11:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  136. DRV:[b]64bit:[/b] - [2013/08/22 10:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
  137. DRV:[b]64bit:[/b] - [2013/08/22 10:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
  138. DRV:[b]64bit:[/b] - [2013/08/22 10:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
  139. DRV:[b]64bit:[/b] - [2013/08/22 10:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
  140. DRV:[b]64bit:[/b] - [2013/08/22 10:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  141. DRV:[b]64bit:[/b] - [2013/08/22 10:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  142. DRV:[b]64bit:[/b] - [2013/08/22 10:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
  143. DRV:[b]64bit:[/b] - [2013/08/22 10:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  144. DRV:[b]64bit:[/b] - [2013/08/22 10:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
  145. DRV:[b]64bit:[/b] - [2013/08/22 10:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
  146. DRV:[b]64bit:[/b] - [2013/08/22 10:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  147. DRV:[b]64bit:[/b] - [2013/08/22 10:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  148. DRV:[b]64bit:[/b] - [2013/08/22 10:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
  149. DRV:[b]64bit:[/b] - [2013/08/22 10:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  150. DRV:[b]64bit:[/b] - [2013/08/22 10:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
  151. DRV:[b]64bit:[/b] - [2013/08/22 10:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
  152. DRV:[b]64bit:[/b] - [2013/08/22 10:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  153. DRV:[b]64bit:[/b] - [2013/08/22 10:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
  154. DRV:[b]64bit:[/b] - [2013/08/22 10:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
  155. DRV:[b]64bit:[/b] - [2013/08/22 10:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  156. DRV:[b]64bit:[/b] - [2013/08/22 10:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
  157. DRV:[b]64bit:[/b] - [2013/08/22 10:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
  158. DRV:[b]64bit:[/b] - [2013/08/22 10:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
  159. DRV:[b]64bit:[/b] - [2013/08/22 10:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
  160. DRV:[b]64bit:[/b] - [2013/08/22 10:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
  161. DRV:[b]64bit:[/b] - [2013/08/22 10:34:22 | 000,265,056 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
  162. DRV:[b]64bit:[/b] - [2013/08/22 10:34:22 | 000,124,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
  163. DRV:[b]64bit:[/b] - [2013/08/22 10:31:28 | 000,034,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
  164. DRV:[b]64bit:[/b] - [2013/08/22 09:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
  165. DRV:[b]64bit:[/b] - [2013/08/22 09:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
  166. DRV:[b]64bit:[/b] - [2013/08/22 09:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
  167. DRV:[b]64bit:[/b] - [2013/08/22 09:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
  168. DRV:[b]64bit:[/b] - [2013/08/22 09:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
  169. DRV:[b]64bit:[/b] - [2013/08/22 09:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
  170. DRV:[b]64bit:[/b] - [2013/08/22 09:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
  171. DRV:[b]64bit:[/b] - [2013/08/22 09:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
  172. DRV:[b]64bit:[/b] - [2013/08/22 09:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
  173. DRV:[b]64bit:[/b] - [2013/08/22 09:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
  174. DRV:[b]64bit:[/b] - [2013/08/22 09:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
  175. DRV:[b]64bit:[/b] - [2013/08/22 09:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  176. DRV:[b]64bit:[/b] - [2013/08/22 09:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
  177. DRV:[b]64bit:[/b] - [2013/08/22 09:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
  178. DRV:[b]64bit:[/b] - [2013/08/22 09:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
  179. DRV:[b]64bit:[/b] - [2013/08/22 06:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
  180. DRV:[b]64bit:[/b] - [2013/08/12 21:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
  181. DRV:[b]64bit:[/b] - [2013/08/09 22:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
  182. DRV:[b]64bit:[/b] - [2013/07/30 16:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
  183. DRV:[b]64bit:[/b] - [2013/07/25 17:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
  184. DRV:[b]64bit:[/b] - [2013/06/18 12:46:17 | 000,591,360 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
  185. DRV:[b]64bit:[/b] - [2012/12/05 22:57:40 | 001,578,128 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTWlanU.sys -- (RtlWlanu)
  186. DRV:[b]64bit:[/b] - [2012/05/12 13:31:00 | 000,121,416 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
  187. DRV:[b]64bit:[/b] - [2011/12/07 20:42:28 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
  188. DRV:[b]64bit:[/b] - [2011/11/25 22:04:40 | 000,027,760 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
  189. DRV:[b]64bit:[/b] - [2011/11/25 22:04:40 | 000,014,448 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
  190. DRV:[b]64bit:[/b] - [2011/05/18 09:08:32 | 000,047,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
  191. DRV:[b]64bit:[/b] - [2011/03/04 13:46:20 | 000,078,976 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
  192. DRV:[b]64bit:[/b] - [2011/03/04 13:46:20 | 000,038,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
  193. DRV:[b]64bit:[/b] - [2010/12/16 12:06:46 | 000,047,232 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
  194. DRV:[b]64bit:[/b] - [2010/06/17 18:15:36 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
  195. DRV:[b]64bit:[/b] - [2010/03/30 09:48:34 | 000,011,832 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdide64.sys -- (amdide64)
  196. DRV:[b]64bit:[/b] - [2009/12/30 11:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
  197. DRV:[b]64bit:[/b] - [2009/06/11 03:59:58 | 000,485,888 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
  198. DRV - [2014/03/17 01:10:00 | 000,032,456 | ---- | M] (CyberLink Corp.) [2015/10/01 23:11:27] [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD14\Common\NavFilter\000.fcl -- ({C5F942FD-1110-4664-86CE-0C6BDA305235})
  199. DRV - [2013/11/21 11:22:10 | 000,115,448 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive)
  200. DRV - [2012/12/29 18:59:38 | 000,028,664 | ---- | M] (Almico Software) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
  201.  
  202.  
  203. [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
  204.  
  205.  
  206. [color=#E56717]========== Internet Explorer ==========[/color]
  207.  
  208. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
  209. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
  210. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
  211. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
  212. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  213. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  214. IE:[b]64bit:[/b] - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  215. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  216. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  217. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  218.  
  219. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
  220. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/pt-br/?ocid=iehp
  221. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR,pt;q=0.8,en-US;q=0.5,en;q=0.3
  222. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 66 2B 62 B3 48 13 D1 01 [binary data]
  223. IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  224. IE - HKCU\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = http://www.google.com/search?q={searchTerms}
  225. IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
  226. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  227.  
  228. [color=#E56717]========== FireFox ==========[/color]
  229.  
  230. FF - prefs.js..browser.search.countryCode: "BR"
  231. FF - prefs.js..browser.search.region: "BR"
  232. FF - prefs.js..browser.startup.homepage: "about:home"
  233. FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:40.0.3
  234. FF - user.js - File not found
  235.  
  236. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll File not found
  237. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  238. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll ()
  239. FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  240. FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  241. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
  242. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
  243.  
  244. 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox Developer Edition 44.0a2\extensions\\Components: C:\PROGRAM FILES\FIREFOX DEVELOPER EDITION\COMPONENTS
  245. 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox Developer Edition 44.0a2\extensions\\Plugins: C:\PROGRAM FILES\FIREFOX DEVELOPER EDITION\PLUGINS
  246. FF - HKEY_CURRENT_USER\software\mozilla\Firefox Developer Edition 44.0a2\extensions\\Components: C:\Program Files\Firefox Developer Edition\components
  247. FF - HKEY_CURRENT_USER\software\mozilla\Firefox Developer Edition 44.0a2\extensions\\Plugins: C:\Program Files\Firefox Developer Edition\plugins
  248.  
  249. [2015/09/18 17:18:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gabriel\AppData\Roaming\mozilla\Extensions
  250. [2015/11/30 23:56:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gabriel\AppData\Roaming\mozilla\Firefox\Profiles\0u7utikd.dev-edition-default\extensions
  251.  
  252. [color=#E56717]========== Chrome ==========[/color]
  253.  
  254. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
  255. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
  256. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
  257. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
  258. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.9.4_0\
  259. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
  260. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\deniojjaaghemnlplaehonnpkbemehkh\1.2.1_0\
  261. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
  262. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.1_1\
  263. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
  264. CHR - Extension: No name found = C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
  265.  
  266. O1 HOSTS File: ([2015/12/01 20:12:35 | 000,000,753 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  267. O1 - Hosts: 127.0.0.1 localhost
  268. O2:[b]64bit:[/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de Programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  269. O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Arquivos de Programas\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  270. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
  271. O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
  272. O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)
  273. O4:[b]64bit:[/b] - HKLM..\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe (IvoSoft)
  274. O4:[b]64bit:[/b] - HKLM..\Run: [SysTrayApp] C:\Arquivos de Programas\IDT\WDM\sttray64.exe (IDT, Inc.)
  275. O4 - HKLM..\Run: [PowerDVD14Agent] C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe (CyberLink Corp.)
  276. O4 - HKCU..\Run: [Sony PC Companion] C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Sony)
  277. O4 - HKCU..\Run: [Unified Remote V3] C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe (Unified Intents AB)
  278. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  279. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  280. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
  281. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
  282. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
  283. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  284. O8:[b]64bit:[/b] - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  285. O8:[b]64bit:[/b] - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
  286. O8 - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  287. O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
  288. O9:[b]64bit:[/b] - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  289. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  290. O9:[b]64bit:[/b] - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  291. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  292. O13 - gopher Prefix: missing
  293. O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan)
  294. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4 201.6.4.116
  295. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC5A1BC-13EC-467F-91EE-9B44877FFF5F}: DhcpNameServer = 8.8.8.8 8.8.4.4 201.6.4.116
  296. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC5A1BC-13EC-467F-91EE-9B44877FFF5F}: NameServer = 8.8.8.8,8.8.4.4,192.168.0.1
  297. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABED063E-4BD2-4B6C-9A4E-94CFC4B4AD71}: DhcpNameServer = 192.168.1.1 192.168.0.1
  298. O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
  299. O18 - Protocol\Handler\ms-help - No CLSID value found
  300. O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
  301. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
  302. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  303. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
  304. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
  305. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  306. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  307. O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de Programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  308. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
  309. O32 - HKLM CDRom: AutoRun - 1
  310. O34 - HKLM BootExecute: (autocheck autochk /k:E *)
  311. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  312. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  313. O35 - HKLM\..comfile [open] -- "%1" %*
  314. O35 - HKLM\..exefile [open] -- "%1" %*
  315. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  316. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  317. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  318. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  319. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  320. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  321.  
  322. NetSvcs:[b]64bit:[/b] lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
  323. NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
  324. NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
  325. NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
  326. NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
  327. NetSvcs:[b]64bit:[/b] MsKeyboardFilter - C:\Windows\SysNative\KeyboardFilterSvc.dll (Microsoft Corporation)
  328.  
  329. CREATERESTOREPOINT
  330. Restore point Set: OTL Restore Point
  331.  
  332. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  333.  
  334. [2015/12/03 21:00:32 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\VS Revo Group
  335. [2015/12/03 21:00:30 | 000,031,800 | ---- | C] (VS Revo Group) -- C:\WINDOWS\SysNative\drivers\revoflt.sys
  336. [2015/12/03 21:00:30 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
  337. [2015/12/03 21:00:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
  338. [2015/12/03 21:00:29 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
  339. [2015/12/03 16:28:10 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Roaming\TeamViewer
  340. [2015/12/03 16:28:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
  341. [2015/12/02 22:59:21 | 000,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\subinacl.exe
  342. [2015/12/02 22:59:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adware Removal Tool by TSA
  343. [2015/12/02 20:44:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
  344. [2015/12/02 00:53:34 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\Documents\Nova pasta (5)
  345. [2015/12/02 00:46:58 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\Documents\Nova pasta (4)
  346. [2015/12/02 00:00:58 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\.android
  347. [2015/12/01 20:33:55 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
  348. [2015/12/01 20:23:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
  349. [2015/12/01 20:23:02 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\Temp
  350. [2015/12/01 20:11:06 | 000,000,000 | ---D | C] -- C:\zoek_backup
  351. [2015/12/01 19:40:17 | 000,000,000 | ---D | C] -- C:\FRST
  352. [2015/12/01 00:34:15 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\WINDOWS\SysNative\bootdelete.exe
  353. [2015/12/01 00:24:41 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
  354. [2015/11/30 23:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
  355. [2015/11/29 21:16:35 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Roaming\Audacity
  356. [2015/11/29 21:16:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
  357. [2015/11/27 23:27:30 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Roaming\Opera Software
  358. [2015/11/27 23:27:30 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\Opera Software
  359. [2015/11/27 23:26:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
  360. [2015/11/26 16:34:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lazesoft Recovery Suite
  361. [2015/11/25 20:06:45 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool
  362. [2015/11/25 19:19:58 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\http___www.julien-manici
  363. [2015/11/25 01:11:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
  364. [2015/11/25 01:11:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
  365. [2015/11/25 01:11:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
  366. [2015/11/25 00:09:24 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\.swt
  367. [2015/11/25 00:09:24 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\.oracle_jre_usage
  368. [2015/11/25 00:09:24 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\.flashTool
  369. [2015/11/25 00:09:12 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Roaming\ADBDriverInstaller
  370. [2015/11/25 00:06:54 | 000,000,000 | ---D | C] -- C:\Flashtool
  371. [2015/11/24 19:31:07 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
  372. [2015/11/24 19:30:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
  373. [2015/11/17 23:23:20 | 000,000,000 | ---D | C] -- C:\Program Files\Firefox Developer Edition
  374. [2015/11/17 19:04:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DRVSTORE
  375. [2015/11/17 19:04:15 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
  376. [2015/11/17 16:35:35 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\NeoSmart_Technologies
  377. [2015/11/17 16:35:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies
  378. [2015/11/17 16:35:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NeoSmart Technologies
  379. [2015/11/11 13:32:26 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
  380. [2015/11/11 13:32:26 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
  381. [2015/11/11 13:32:26 | 000,397,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
  382. [2015/11/11 13:32:26 | 000,340,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
  383. [2015/11/11 13:32:26 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
  384. [2015/11/11 13:32:26 | 000,137,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncrypt.dll
  385. [2015/11/11 13:32:26 | 000,106,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
  386. [2015/11/11 13:32:26 | 000,091,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
  387. [2015/11/11 13:32:25 | 007,455,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
  388. [2015/11/11 13:32:25 | 001,659,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
  389. [2015/11/11 13:32:25 | 001,519,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
  390. [2015/11/11 13:32:25 | 001,487,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
  391. [2015/11/11 13:32:25 | 001,355,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
  392. [2015/11/11 13:32:25 | 000,558,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
  393. [2015/11/11 13:32:25 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
  394. [2015/11/11 13:32:25 | 000,183,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AuthHost.exe
  395. [2015/11/11 13:32:24 | 001,380,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
  396. [2015/11/11 13:32:24 | 001,091,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
  397. [2015/11/11 13:32:24 | 000,825,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pmcsnap.dll
  398. [2015/11/11 13:32:24 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
  399. [2015/11/11 13:32:24 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
  400. [2015/11/11 13:32:24 | 000,260,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ppcsnap.dll
  401. [2015/11/11 13:32:24 | 000,155,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\tpm.sys
  402. [2015/11/11 13:32:23 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
  403. [2015/11/11 13:32:23 | 000,561,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
  404. [2015/11/11 13:32:23 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FWPUCLNT.DLL
  405. [2015/11/11 13:32:23 | 000,272,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FWPUCLNT.DLL
  406. [2015/11/11 13:32:23 | 000,136,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wfplwfs.sys
  407. [2015/11/11 13:32:20 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
  408. [2015/11/11 13:32:19 | 002,243,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
  409. [2015/11/11 13:32:19 | 000,891,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
  410. [2015/11/11 13:32:19 | 000,721,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
  411. [2015/11/11 13:32:19 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
  412. [2015/11/11 13:32:19 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
  413. [2015/11/11 13:32:19 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
  414. [2015/11/11 13:32:19 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
  415. [2015/11/11 13:32:19 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
  416. [2015/11/11 13:32:19 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
  417. [2015/11/11 13:32:19 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
  418. [2015/11/11 13:31:28 | 005,990,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
  419. [2015/11/11 13:31:28 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
  420. [2015/11/11 13:31:28 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
  421. [2015/11/11 13:31:27 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
  422. [2015/11/11 13:31:27 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
  423. [2015/11/11 13:31:26 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
  424. [2015/11/11 13:31:26 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
  425. [2015/11/11 13:31:26 | 000,585,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
  426. [2015/11/06 19:38:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Megacubo
  427. [2015/11/06 19:38:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Megacubo
  428. [2015/11/04 15:48:46 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\Diagnostics
  429. [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
  430. [1 C:\*.tmp files -> C:\*.tmp -> ]
  431.  
  432. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  433.  
  434. [2015/12/03 22:44:00 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
  435. [2015/12/03 22:08:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
  436. [2015/12/03 21:08:00 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
  437. [2015/12/03 21:04:10 | 000,002,273 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
  438. [2015/12/02 22:59:21 | 000,290,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\subinacl.exe
  439. [2015/12/02 19:25:18 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
  440. [2015/12/02 19:25:10 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
  441. [2015/12/02 19:25:06 | 858,406,911 | -HS- | M] () -- C:\hiberfil.sys
  442. [2015/12/02 19:22:14 | 000,024,064 | ---- | M] () -- C:\WINDOWS\zoek-delete.exe
  443. [2015/12/02 00:43:46 | 001,797,166 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
  444. [2015/12/02 00:43:46 | 000,774,702 | ---- | M] () -- C:\WINDOWS\SysNative\prfh0416.dat
  445. [2015/12/02 00:43:46 | 000,722,278 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
  446. [2015/12/02 00:43:46 | 000,158,296 | ---- | M] () -- C:\WINDOWS\SysNative\prfc0416.dat
  447. [2015/12/02 00:43:46 | 000,135,394 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
  448. [2015/12/01 20:12:35 | 000,000,753 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\etc\hosts
  449. [2015/12/01 00:34:15 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\WINDOWS\SysNative\bootdelete.exe
  450. [2015/12/01 00:14:28 | 000,113,880 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
  451. [2015/11/30 23:46:29 | 000,030,848 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\TrueSight.sys
  452. [2015/11/30 23:31:19 | 000,018,099 | ---- | M] () -- C:\WINDOWS\unins000.dat
  453. [2015/11/30 23:31:18 | 001,174,979 | ---- | M] () -- C:\WINDOWS\unins000.exe
  454. [2015/11/29 23:08:16 | 000,011,776 | ---- | M] () -- C:\WINDOWS\SysNative\ardnat.exe
  455. [2015/11/28 00:31:42 | 000,000,936 | ---- | M] () -- C:\Users\Public\Desktop\Firefox Developer Edition.lnk
  456. [2015/11/25 00:08:50 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_wpdcomp_01_11_00.Wdf
  457. [2015/11/17 16:35:29 | 000,001,229 | ---- | M] () -- C:\Users\Public\Desktop\EasyBCD 2.3.lnk
  458. [2015/11/15 20:57:21 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
  459. [2015/11/12 13:22:15 | 000,481,680 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
  460. [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
  461. [1 C:\*.tmp files -> C:\*.tmp -> ]
  462.  
  463. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  464.  
  465. [2015/12/03 21:04:10 | 000,002,302 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
  466. [2015/12/03 21:04:10 | 000,002,273 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
  467. [2015/12/03 21:03:04 | 000,001,092 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
  468. [2015/12/03 21:03:04 | 000,001,088 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
  469. [2015/12/03 16:52:57 | 000,000,983 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
  470. [2015/12/02 19:24:19 | 000,024,064 | ---- | C] () -- C:\WINDOWS\zoek-delete.exe
  471. [2015/11/30 23:46:29 | 000,030,848 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\TrueSight.sys
  472. [2015/11/30 23:31:18 | 001,174,979 | ---- | C] () -- C:\WINDOWS\unins000.exe
  473. [2015/11/30 23:31:18 | 000,018,099 | ---- | C] () -- C:\WINDOWS\unins000.dat
  474. [2015/11/29 21:16:31 | 000,001,031 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
  475. [2015/11/27 23:27:11 | 000,001,147 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
  476. [2015/11/25 00:08:50 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_wpdcomp_01_11_00.Wdf
  477. [2015/11/17 16:35:29 | 000,001,229 | ---- | C] () -- C:\Users\Public\Desktop\EasyBCD 2.3.lnk
  478. [2015/11/11 13:32:26 | 000,414,559 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
  479. [2015/09/29 22:52:54 | 000,000,001 | ---- | C] () -- C:\Users\Gabriel\AppData\Local\llftool.4.40.agreement
  480. [2015/09/22 15:10:38 | 000,107,008 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
  481. [2015/09/22 15:10:22 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
  482. [2015/09/21 17:41:42 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
  483. [2015/09/20 22:46:06 | 000,000,122 | ---- | C] () -- C:\WINDOWS\wa.INI
  484.  
  485. [color=#E56717]========== ZeroAccess Check ==========[/color]
  486.  
  487. [2015/10/09 19:50:20 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
  488.  
  489. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  490.  
  491. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  492.  
  493. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  494.  
  495. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  496.  
  497. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  498. "" = C:\Windows\SysNative\shell32.dll -- [2015/08/27 00:43:09 | 022,372,152 | ---- | M] (Microsoft Corporation)
  499. "ThreadingModel" = Apartment
  500.  
  501. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  502. "" = %SystemRoot%\system32\shell32.dll -- [2015/08/27 00:42:51 | 019,795,904 | ---- | M] (Microsoft Corporation)
  503. "ThreadingModel" = Apartment
  504.  
  505. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  506. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/10/28 23:19:43 | 001,013,760 | ---- | M] (Microsoft Corporation)
  507. "ThreadingModel" = Free
  508.  
  509. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  510. "" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/28 22:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
  511. "ThreadingModel" = Free
  512.  
  513. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  514. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/10/28 23:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
  515. "ThreadingModel" = Both
  516.  
  517. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  518.  
  519. [color=#E56717]========== LOP Check ==========[/color]
  520.  
  521. [2015/11/25 00:09:12 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ADBDriverInstaller
  522. [2015/10/20 00:11:06 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Anvsoft
  523. [2015/11/29 21:28:47 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Audacity
  524. [2015/11/28 18:25:44 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\BitTorrent
  525. [2015/09/18 17:04:16 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ClassicShell
  526. [2015/10/01 01:08:12 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\HD Tune Pro
  527. [2015/09/26 00:05:08 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ImgBurn
  528. [2015/10/01 15:55:03 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\IObit
  529. [2015/09/20 21:20:06 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\MotioninJoy
  530. [2015/11/27 23:27:30 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Opera Software
  531. [2015/09/18 17:07:23 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\PhotoFiltre Studio X
  532. [2015/12/03 16:28:10 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\TeamViewer
  533. [2015/10/26 23:28:16 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Unified Remote
  534. [2015/09/26 00:13:39 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\WinAVI
  535.  
  536. [color=#E56717]========== Purity Check ==========[/color]
  537.  
  538.  
  539.  
  540. [color=#E56717]========== Custom Scans ==========[/color]
  541.  
  542. [color=#A23BEC]< %APPDATA%\Local\*. >[/color]
  543.  
  544. [color=#A23BEC]< %APPDATA%\*.exe /s >[/color]
  545. [2015/11/25 00:09:12 | 000,228,352 | ---- | M] (ADBDriver.com) -- C:\Users\Gabriel\AppData\Roaming\ADBDriverInstaller\usb_driver\ADBDriverInstallerX64.exe
  546. [2015/09/18 16:15:04 | 005,638,697 | ---- | M] () -- C:\Users\Gabriel\AppData\Roaming\Anvsoft\Common\youtube-dl.exe
  547. [2015/10/12 23:56:03 | 001,977,192 | ---- | M] (BitTorrent Inc.) -- C:\Users\Gabriel\AppData\Roaming\BitTorrent\BitTorrent.exe
  548. [2015/09/20 22:58:10 | 001,910,376 | ---- | M] (BitTorrent Inc.) -- C:\Users\Gabriel\AppData\Roaming\BitTorrent\updates\7.9.5_41074.exe
  549. [2015/10/12 23:56:03 | 001,977,192 | ---- | M] (BitTorrent Inc.) -- C:\Users\Gabriel\AppData\Roaming\BitTorrent\updates\7.9.5_41203.exe
  550. [2015/09/20 23:09:50 | 000,336,896 | ---- | M] (BitTorrent Inc.) -- C:\Users\Gabriel\AppData\Roaming\BitTorrent\updates\7.9.5_41074\utorrentie.exe
  551. [2015/10/22 00:54:58 | 000,336,896 | ---- | M] (BitTorrent Inc.) -- C:\Users\Gabriel\AppData\Roaming\BitTorrent\updates\7.9.5_41203\utorrentie.exe
  552. [1999/04/23 14:56:28 | 000,177,152 | ---- | M] () -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\clokspl.exe
  553. [2012/03/17 22:51:04 | 002,595,931 | ---- | M] (Igor Pavlov) -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\GfxUpdate.exe
  554. [1999/01/09 12:42:00 | 000,132,608 | ---- | M] () -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\Landgen.exe
  555. [1999/01/28 17:00:24 | 000,021,504 | ---- | M] () -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\RegSetup.exe
  556. [2001/12/03 06:38:50 | 000,032,768 | ---- | M] () -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\Silkworm_patch.exe
  557. [2012/12/20 08:01:16 | 003,227,648 | ---- | M] (Team17 Software Ltd) -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\wa.exe
  558. [1 C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\*.tmp files -> C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\*.tmp -> ]
  559. [1998/12/14 16:49:04 | 000,274,944 | ---- | M] (Team 17 Ltd.) -- C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Team17\Worms Armageddon\User\BankEditor.exe
  560.  
  561. [color=#A23BEC]< %APPDATA%\*. >[/color]
  562. [2015/11/25 00:09:12 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ADBDriverInstaller
  563. [2015/11/06 19:41:01 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Adobe
  564. [2015/10/20 00:11:06 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Anvsoft
  565. [2015/11/29 21:28:47 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Audacity
  566. [2015/11/28 18:25:44 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\BitTorrent
  567. [2015/09/18 17:04:16 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ClassicShell
  568. [2015/10/02 00:13:16 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\CyberLink
  569. [2015/10/01 01:08:12 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\HD Tune Pro
  570. [2015/09/22 19:22:03 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Identities
  571. [2015/09/26 00:05:08 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ImgBurn
  572. [2015/10/01 15:55:03 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\IObit
  573. [2015/11/06 19:41:02 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Macromedia
  574. [2015/11/12 22:10:43 | 000,000,000 | --SD | M] -- C:\Users\Gabriel\AppData\Roaming\Microsoft
  575. [2015/09/20 21:20:06 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\MotioninJoy
  576. [2015/09/18 17:18:20 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Mozilla
  577. [2015/09/26 00:13:40 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\NVIDIA
  578. [2015/11/27 23:27:30 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Opera Software
  579. [2015/09/18 17:07:23 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\PhotoFiltre Studio X
  580. [2015/12/03 16:28:10 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\TeamViewer
  581. [2015/10/26 23:28:16 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Unified Remote
  582. [2015/09/26 00:13:39 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\WinAVI
  583. [2015/09/18 19:39:51 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\WinRAR
  584.  
  585. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*.* >[/color]
  586. [2015/12/03 01:29:13 | 000,162,346 | -H-- | M] () -- C:\Users\Gabriel\AppData\Local\IconCache.db
  587. [2015/09/29 22:52:54 | 000,000,001 | ---- | M] () -- C:\Users\Gabriel\AppData\Local\llftool.4.40.agreement
  588.  
  589. [color=#A23BEC]< %systemroot%\assembly\tmp\*.* /S /MD5 >[/color]
  590.  
  591. [color=#A23BEC]< %systemroot%\assembly\temp\*.* /S /MD5 >[/color]
  592.  
  593. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Local\*.* >[/color]
  594.  
  595. [color=#A23BEC]< %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* >[/color]
  596.  
  597. [color=#A23BEC]< %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* >[/color]
  598.  
  599. [color=#A23BEC]< %windir%\Installer\*.* >[/color]
  600. [2015/09/18 17:02:26 | 004,775,936 | ---- | M] () -- C:\WINDOWS\Installer\16125e.msi
  601. [2015/09/18 23:49:37 | 000,339,968 | ---- | M] () -- C:\WINDOWS\Installer\18e028b.msi
  602. [2015/09/18 23:49:51 | 000,368,640 | ---- | M] () -- C:\WINDOWS\Installer\18e02bf.msi
  603. [2015/09/18 23:49:59 | 000,303,104 | ---- | M] () -- C:\WINDOWS\Installer\18e02c7.msi
  604. [2015/09/18 23:50:04 | 001,024,000 | ---- | M] () -- C:\WINDOWS\Installer\18e08c2.msi
  605. [2015/09/19 01:35:59 | 000,929,792 | ---- | M] () -- C:\WINDOWS\Installer\1ef8278.msi
  606. [2008/08/08 15:11:02 | 000,232,960 | ---- | M] () -- C:\WINDOWS\Installer\2186542.msi
  607. [2009/07/12 13:16:26 | 000,223,232 | ---- | M] () -- C:\WINDOWS\Installer\218654b.msi
  608. [2010/12/09 02:08:18 | 000,614,400 | ---- | M] () -- C:\WINDOWS\Installer\21bcd5b.msi
  609. [2014/03/14 03:40:02 | 000,143,360 | ---- | M] () -- C:\WINDOWS\Installer\2247e24.msi
  610. [2014/03/14 03:40:02 | 000,143,360 | ---- | M] () -- C:\WINDOWS\Installer\2247e2a.msi
  611. [2014/03/12 20:11:48 | 000,143,360 | ---- | M] () -- C:\WINDOWS\Installer\2247e30.msi
  612. [2014/03/12 20:11:48 | 000,143,360 | ---- | M] () -- C:\WINDOWS\Installer\2247e36.msi
  613. [2015/09/05 00:31:30 | 018,779,136 | R--- | M] () -- C:\WINDOWS\Installer\2dc80e.msp
  614. [2015/09/05 00:31:08 | 000,942,592 | R--- | M] () -- C:\WINDOWS\Installer\2dc82f.msp
  615. [2015/09/18 15:27:30 | 039,603,200 | R--- | M] () -- C:\WINDOWS\Installer\2dc852.msp
  616. [2015/09/18 15:27:36 | 025,676,288 | R--- | M] () -- C:\WINDOWS\Installer\2dc869.msp
  617. [2015/09/18 15:27:10 | 020,389,888 | R--- | M] () -- C:\WINDOWS\Installer\2dc882.msp
  618. [2015/09/18 15:26:48 | 044,496,896 | R--- | M] () -- C:\WINDOWS\Installer\2dc89b.msp
  619. [2015/09/18 15:27:06 | 009,426,944 | R--- | M] () -- C:\WINDOWS\Installer\2dc8b3.msp
  620. [2015/09/18 15:44:34 | 020,587,008 | R--- | M] () -- C:\WINDOWS\Installer\2dc8e2.msp
  621. [2015/09/18 15:43:40 | 001,692,672 | R--- | M] () -- C:\WINDOWS\Installer\2dc8ea.msp
  622. [2015/09/18 15:26:36 | 003,446,272 | R--- | M] () -- C:\WINDOWS\Installer\2dc902.msp
  623. [2015/09/05 00:31:04 | 005,691,392 | R--- | M] () -- C:\WINDOWS\Installer\2dc91b.msp
  624. [2011/04/16 09:44:26 | 002,770,944 | ---- | M] () -- C:\WINDOWS\Installer\2f3ded.msi
  625. [2011/04/19 05:54:14 | 000,227,328 | ---- | M] () -- C:\WINDOWS\Installer\2f3df6.msi
  626. [2015/09/20 15:03:30 | 003,905,024 | ---- | M] () -- C:\WINDOWS\Installer\5177e.msi
  627. [2015/09/20 15:03:42 | 002,508,800 | ---- | M] () -- C:\WINDOWS\Installer\51786.msi
  628. [2015/09/20 15:03:53 | 002,505,216 | ---- | M] () -- C:\WINDOWS\Installer\5178f.msi
  629. [2015/09/20 15:04:10 | 002,508,800 | ---- | M] () -- C:\WINDOWS\Installer\51797.msi
  630. [2015/09/20 15:04:12 | 002,867,712 | ---- | M] () -- C:\WINDOWS\Installer\517a0.msi
  631. [2015/09/20 15:04:43 | 000,873,472 | ---- | M] () -- C:\WINDOWS\Installer\517a8.msi
  632. [2015/09/20 15:04:36 | 000,881,152 | ---- | M] () -- C:\WINDOWS\Installer\517b0.msi
  633. [2015/09/20 15:04:29 | 000,875,520 | ---- | M] () -- C:\WINDOWS\Installer\517b8.msi
  634. [2015/09/20 15:04:29 | 000,869,888 | ---- | M] () -- C:\WINDOWS\Installer\517c0.msi
  635. [2015/09/20 15:04:44 | 002,504,704 | ---- | M] () -- C:\WINDOWS\Installer\517c8.msi
  636. [2015/09/20 15:04:49 | 002,520,064 | ---- | M] () -- C:\WINDOWS\Installer\517d2.msi
  637. [2015/09/20 15:05:28 | 003,128,320 | ---- | M] () -- C:\WINDOWS\Installer\517da.msi
  638. [2015/09/20 15:05:41 | 000,875,008 | ---- | M] () -- C:\WINDOWS\Installer\517e2.msi
  639. [2015/09/20 15:05:42 | 002,515,968 | ---- | M] () -- C:\WINDOWS\Installer\517eb.msi
  640. [2015/09/20 15:05:46 | 002,525,184 | ---- | M] () -- C:\WINDOWS\Installer\517f4.msi
  641. [2015/09/20 15:06:21 | 001,992,192 | ---- | M] () -- C:\WINDOWS\Installer\517fd.msi
  642. [2015/09/20 15:06:36 | 027,195,904 | ---- | M] () -- C:\WINDOWS\Installer\51807.msi
  643. [2013/10/16 04:01:46 | 025,647,616 | R--- | M] () -- C:\WINDOWS\Installer\523bde.msp
  644. [2015/03/23 00:25:44 | 009,739,776 | R--- | M] () -- C:\WINDOWS\Installer\523bf9.msp
  645. [2015/07/16 09:21:06 | 001,071,616 | R--- | M] () -- C:\WINDOWS\Installer\523c12.msp
  646. [2015/06/17 16:21:26 | 020,387,840 | R--- | M] () -- C:\WINDOWS\Installer\523c2d.msp
  647. [2015/06/17 16:23:30 | 018,628,608 | R--- | M] () -- C:\WINDOWS\Installer\523c46.msp
  648. [2015/08/13 07:18:24 | 001,554,432 | R--- | M] () -- C:\WINDOWS\Installer\523c59.msp
  649. [2015/08/13 07:19:22 | 008,860,672 | R--- | M] () -- C:\WINDOWS\Installer\523c69.msp
  650. [2015/08/13 07:19:06 | 009,796,096 | R--- | M] () -- C:\WINDOWS\Installer\523c7a.msp
  651. [2015/07/16 09:20:22 | 044,880,896 | R--- | M] () -- C:\WINDOWS\Installer\523c95.msp
  652. [2015/08/13 07:17:52 | 039,601,152 | R--- | M] () -- C:\WINDOWS\Installer\523cb1.msp
  653. [2013/07/24 09:15:36 | 001,233,408 | R--- | M] () -- C:\WINDOWS\Installer\523cca.msp
  654. [2015/02/17 18:32:04 | 000,739,328 | R--- | M] () -- C:\WINDOWS\Installer\523cd4.msp
  655. [2015/07/16 09:19:40 | 000,694,784 | R--- | M] () -- C:\WINDOWS\Installer\523ced.msp
  656. [2013/09/07 00:34:24 | 021,882,880 | R--- | M] () -- C:\WINDOWS\Installer\523d06.msp
  657. [2015/03/23 00:30:52 | 044,489,216 | R--- | M] () -- C:\WINDOWS\Installer\523d2b.msp
  658. [2015/03/23 00:31:24 | 000,925,184 | R--- | M] () -- C:\WINDOWS\Installer\523d36.msp
  659. [2014/10/03 17:57:20 | 000,434,688 | R--- | M] () -- C:\WINDOWS\Installer\523d62.msp
  660. [2014/11/12 00:59:14 | 002,979,328 | R--- | M] () -- C:\WINDOWS\Installer\523d7e.msp
  661. [2013/12/18 18:56:04 | 022,602,752 | R--- | M] () -- C:\WINDOWS\Installer\523da9.msp
  662. [2015/02/17 18:39:16 | 001,004,032 | R--- | M] () -- C:\WINDOWS\Installer\523dbe.msp
  663. [2013/07/24 09:28:16 | 003,499,008 | R--- | M] () -- C:\WINDOWS\Installer\523dd7.msp
  664. [2014/04/02 03:45:38 | 003,068,416 | R--- | M] () -- C:\WINDOWS\Installer\523df0.msp
  665. [2015/05/14 16:35:48 | 000,591,360 | R--- | M] () -- C:\WINDOWS\Installer\523dfa.msp
  666. [2015/05/14 16:35:46 | 013,219,840 | R--- | M] () -- C:\WINDOWS\Installer\523e1e.msp
  667. [2015/05/22 13:59:52 | 005,337,600 | R--- | M] () -- C:\WINDOWS\Installer\523e41.msp
  668. [2015/07/16 09:19:48 | 000,372,736 | R--- | M] () -- C:\WINDOWS\Installer\523e5a.msp
  669. [2015/09/03 11:40:58 | 000,673,792 | R--- | M] () -- C:\WINDOWS\Installer\523e71.msp
  670. [2015/08/13 07:33:26 | 020,548,608 | R--- | M] () -- C:\WINDOWS\Installer\523ea2.msp
  671. [2015/08/13 07:32:30 | 001,692,672 | R--- | M] () -- C:\WINDOWS\Installer\523ead.msp
  672. [2014/11/20 11:05:30 | 002,405,888 | R--- | M] () -- C:\WINDOWS\Installer\523ec6.msp
  673. [2014/07/18 06:00:36 | 000,676,864 | R--- | M] () -- C:\WINDOWS\Installer\523edf.msp
  674. [2013/12/18 18:56:04 | 009,469,440 | R--- | M] () -- C:\WINDOWS\Installer\523efa.msp
  675. [2013/08/14 03:35:34 | 000,646,144 | R--- | M] () -- C:\WINDOWS\Installer\523f13.msp
  676. [2015/05/22 14:00:00 | 009,428,480 | R--- | M] () -- C:\WINDOWS\Installer\523f2c.msp
  677. [2014/11/12 01:00:20 | 000,802,304 | R--- | M] () -- C:\WINDOWS\Installer\523f45.msp
  678. [2013/10/25 18:42:58 | 001,742,848 | R--- | M] () -- C:\WINDOWS\Installer\523f5e.msp
  679. [2014/10/03 17:57:30 | 003,070,976 | R--- | M] () -- C:\WINDOWS\Installer\523f77.msp
  680. [2014/04/17 17:02:58 | 000,402,432 | R--- | M] () -- C:\WINDOWS\Installer\523f90.msp
  681. [2015/07/23 00:41:30 | 001,941,504 | R--- | M] () -- C:\WINDOWS\Installer\523fa9.msp
  682. [2015/08/19 04:50:50 | 044,889,600 | R--- | M] () -- C:\WINDOWS\Installer\523fc2.msp
  683. [2013/07/24 09:07:20 | 004,108,288 | R--- | M] () -- C:\WINDOWS\Installer\523fdc.msp
  684. [2015/07/16 09:19:38 | 009,431,552 | R--- | M] () -- C:\WINDOWS\Installer\523ff5.msp
  685. [2015/06/24 02:19:24 | 002,838,528 | R--- | M] () -- C:\WINDOWS\Installer\52400e.msp
  686. [2015/03/23 00:43:32 | 000,402,944 | R--- | M] () -- C:\WINDOWS\Installer\524018.msp
  687. [2015/03/23 00:15:48 | 003,099,136 | R--- | M] () -- C:\WINDOWS\Installer\52403a.msp
  688. [2013/09/07 00:33:14 | 001,952,256 | R--- | M] () -- C:\WINDOWS\Installer\524053.msp
  689. [2015/03/23 00:40:04 | 024,779,776 | R--- | M] () -- C:\WINDOWS\Installer\524075.msp
  690. [2014/11/20 11:05:38 | 000,170,496 | R--- | M] () -- C:\WINDOWS\Installer\52408e.msp
  691. [2015/08/13 07:16:52 | 000,286,208 | R--- | M] () -- C:\WINDOWS\Installer\5240a7.msp
  692. [2015/07/16 09:21:28 | 024,785,408 | R--- | M] () -- C:\WINDOWS\Installer\5240bf.msp
  693. [2015/08/13 07:16:56 | 044,499,456 | R--- | M] () -- C:\WINDOWS\Installer\5240d9.msp
  694. [2015/05/14 17:09:16 | 001,753,600 | R--- | M] () -- C:\WINDOWS\Installer\5240f2.msp
  695. [2013/12/18 19:06:36 | 003,619,840 | R--- | M] () -- C:\WINDOWS\Installer\524119.msp
  696. [2015/04/01 13:29:14 | 005,480,448 | R--- | M] () -- C:\WINDOWS\Installer\524133.msp
  697. [2015/06/25 23:59:22 | 000,147,456 | ---- | M] () -- C:\WINDOWS\Installer\5266a6c.msi
  698. [2015/06/25 23:59:42 | 000,143,360 | ---- | M] () -- C:\WINDOWS\Installer\5266a72.msi
  699. [2015/06/26 00:00:20 | 000,147,456 | ---- | M] () -- C:\WINDOWS\Installer\5266a82.msi
  700. [2015/06/26 00:00:06 | 000,143,360 | ---- | M] () -- C:\WINDOWS\Installer\5266a9a.msi
  701. [2015/12/03 21:03:04 | 000,045,056 | ---- | M] () -- C:\WINDOWS\Installer\584afc8.msi
  702. [2012/02/13 22:30:44 | 000,475,136 | ---- | M] () -- C:\WINDOWS\Installer\747bc9.msi
  703. [2011/03/25 00:13:08 | 006,755,840 | ---- | M] () -- C:\WINDOWS\Installer\7aa3f.msi
  704. [2015/10/30 23:10:20 | 020,573,696 | R--- | M] () -- C:\WINDOWS\Installer\a5b384f.msp
  705. [2015/10/14 09:56:40 | 025,682,432 | R--- | M] () -- C:\WINDOWS\Installer\a5b3866.msp
  706. [2015/10/14 10:42:48 | 000,403,456 | R--- | M] () -- C:\WINDOWS\Installer\a5b3875.msp
  707. [2015/10/14 10:43:20 | 039,828,480 | R--- | M] () -- C:\WINDOWS\Installer\a5b3895.msp
  708. [2015/10/14 09:45:20 | 044,534,272 | R--- | M] () -- C:\WINDOWS\Installer\a5b38b5.msp
  709. [2015/10/14 09:54:52 | 013,907,968 | R--- | M] () -- C:\WINDOWS\Installer\a5b38df.msp
  710. [2015/10/01 08:05:58 | 003,904,000 | R--- | M] () -- C:\WINDOWS\Installer\a5b390c.msp
  711. [2015/10/14 09:55:08 | 009,788,416 | R--- | M] () -- C:\WINDOWS\Installer\a5b3914.msp
  712. [2015/10/14 09:54:40 | 045,109,248 | R--- | M] () -- C:\WINDOWS\Installer\a5b3942.msp
  713. [2015/10/20 20:21:06 | 020,641,280 | R--- | M] () -- C:\WINDOWS\Installer\a5b3965.msp
  714. [2015/10/14 09:45:36 | 018,868,224 | R--- | M] () -- C:\WINDOWS\Installer\a5b3983.msp
  715. [2015/10/14 09:53:20 | 003,444,736 | R--- | M] () -- C:\WINDOWS\Installer\a5b39a2.msp
  716. [2015/10/14 09:45:52 | 006,595,584 | R--- | M] () -- C:\WINDOWS\Installer\a5b39bb.msp
  717. [2015/10/27 17:23:34 | 000,672,768 | R--- | M] () -- C:\WINDOWS\Installer\a5b39cb.msp
  718. [2015/10/14 09:45:20 | 000,090,624 | R--- | M] () -- C:\WINDOWS\Installer\a5b39e2.msp
  719. [2015/10/14 09:55:30 | 009,037,824 | R--- | M] () -- C:\WINDOWS\Installer\a5b39fe.msp
  720. [2015/06/17 16:23:28 | 000,625,152 | R--- | M] () -- C:\WINDOWS\Installer\b6643b.msp
  721. [2011/07/21 14:50:16 | 000,204,800 | R--- | M] () -- C:\WINDOWS\Installer\b664d4.msp
  722. [2015/08/13 07:16:42 | 003,449,344 | R--- | M] () -- C:\WINDOWS\Installer\b664f5.msp
  723. [2014/09/03 06:17:54 | 000,163,840 | ---- | M] () -- C:\WINDOWS\Installer\b72a88.msi
  724. [2014/09/03 06:17:54 | 004,028,928 | R--- | M] () -- C:\WINDOWS\Installer\b72a89.msp
  725. [2014/09/03 06:17:54 | 000,177,664 | ---- | M] () -- C:\WINDOWS\Installer\b72a92.msi
  726. [2014/09/03 06:17:54 | 004,637,184 | R--- | M] () -- C:\WINDOWS\Installer\b72a93.msp
  727. [2014/09/03 01:32:04 | 000,548,352 | ---- | M] () -- C:\WINDOWS\Installer\b72aab.msi
  728. [2014/09/03 02:17:26 | 000,437,760 | ---- | M] () -- C:\WINDOWS\Installer\b72ab7.msi
  729. [2013/08/14 03:41:54 | 000,209,408 | R--- | M] () -- C:\WINDOWS\Installer\b72ace.msp
  730. [2011/10/27 00:23:38 | 018,386,944 | R--- | M] () -- C:\WINDOWS\Installer\b72aef.msp
  731. [2011/10/27 00:18:48 | 001,008,128 | R--- | M] () -- C:\WINDOWS\Installer\b72b04.msp
  732. [2012/03/07 16:03:04 | 026,386,944 | R--- | M] () -- C:\WINDOWS\Installer\b72b37.msp
  733. [2012/03/07 16:01:18 | 001,750,528 | R--- | M] () -- C:\WINDOWS\Installer\b72b43.msp
  734. [2011/10/26 23:50:00 | 000,595,456 | R--- | M] () -- C:\WINDOWS\Installer\b72b4d.msp
  735. [2011/10/26 23:49:56 | 016,777,216 | R--- | M] () -- C:\WINDOWS\Installer\b72b70.msp
  736. [2011/07/21 14:42:12 | 003,222,016 | R--- | M] () -- C:\WINDOWS\Installer\b72b95.msp
  737. [2012/03/21 06:31:30 | 000,133,120 | R--- | M] () -- C:\WINDOWS\Installer\b72b9f.msp
  738. [2012/03/21 06:30:10 | 001,868,288 | R--- | M] () -- C:\WINDOWS\Installer\b72bb9.msp
  739. [2013/06/27 23:01:00 | 011,510,272 | R--- | M] () -- C:\WINDOWS\Installer\bf3328.msp
  740. [2013/06/27 23:17:46 | 024,506,880 | R--- | M] () -- C:\WINDOWS\Installer\bf3335.msp
  741. [2013/06/27 23:02:40 | 003,877,376 | R--- | M] () -- C:\WINDOWS\Installer\bf338d.msp
  742. [2013/07/17 12:15:02 | 796,182,528 | R--- | M] () -- C:\WINDOWS\Installer\bf34fa.msp
  743. [2013/06/27 23:18:18 | 032,299,008 | R--- | M] () -- C:\WINDOWS\Installer\bf351e.msp
  744. [2013/06/27 23:13:06 | 011,828,736 | R--- | M] () -- C:\WINDOWS\Installer\bf3533.msp
  745. [2013/06/27 23:00:02 | 005,182,976 | R--- | M] () -- C:\WINDOWS\Installer\bf3542.msp
  746. [2013/06/27 23:03:20 | 001,656,832 | R--- | M] () -- C:\WINDOWS\Installer\bf354b.msp
  747. [2013/06/27 23:06:08 | 005,625,344 | R--- | M] () -- C:\WINDOWS\Installer\bf356a.msp
  748. [2015/11/19 20:02:08 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{0D3E9E15-DE7A-300B-96F1-B4AF12B96488}
  749. [2015/09/26 00:13:30 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{0F931735-0098-4FF6-A49D-17882A294F51}
  750. [2015/10/26 23:28:49 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
  751. [2015/10/09 19:51:36 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{16793295-2366-40F7-A045-A3E42A81365E}
  752. [2015/10/02 00:11:02 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
  753. [2015/12/03 21:08:00 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
  754. [2015/10/02 15:16:12 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
  755. [2015/11/17 19:04:33 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{8D9294AA-BCC6-C17A-0A3F-AC6BC020840B}
  756. [2015/10/26 23:29:13 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{929FBD26-9020-399B-9A7A-751D61F0B942}
  757. [2015/10/02 00:10:55 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{9A25302D-30C0-39D9-BD6F-21E6EC160475}
  758. [2015/10/02 15:16:24 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{9BE518E6-ECC6-35A9-88E4-87755C07200F}
  759. [2015/11/27 23:23:59 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{9C0F80FF-8C45-466C-83E1-09AA7ED1CE34}
  760. [2015/11/19 20:02:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}
  761. [2015/10/26 23:29:11 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
  762. [2015/11/19 20:02:09 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{BC958BD2-5DAC-3862-BB1A-C1BE0790438D}
  763. [2015/11/19 20:02:39 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}
  764. [2015/10/26 23:28:50 | 000,020,480 | ---- | M] () -- C:\WINDOWS\Installer\SourceHash{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
  765.  
  766. [color=#A23BEC]< %windir%\tasks\*.* /s >[/color]
  767. [2015/12/03 22:44:00 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
  768. [2015/12/03 21:08:00 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
  769. [2015/12/03 22:08:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
  770. [2015/12/02 19:25:42 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
  771.  
  772. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes >[/color]
  773. "DefaultScope" = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  774.  
  775. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
  776.  
  777. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes >[/color]
  778. "DefaultScope" = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  779. "KnownProvidersUpgradeTime" = 75 D6 D9 F7 75 2D D1 01 [binary data]
  780. "Version" = 4
  781. "UpgradeTime" = 1D FD A0 F8 75 2D D1 01 [binary data]
  782. "DefaultPackCorrection" = 1
  783. "DefaultPackNTCorrection" = 1
  784.  
  785. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}]
  786.  
  787. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
  788.  
  789. [color=#A23BEC]< %systemroot%\system32\Tasks\*.* /s >[/color]
  790.  
  791. [color=#A23BEC]< %systemroot%\system32\tasks\*.* /s /64 >[/color]
  792. [2015/11/28 00:44:25 | 000,003,790 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater
  793. [2015/09/18 17:01:35 | 000,003,092 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Aero Glass
  794. [2015/09/28 18:11:12 | 000,002,798 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC
  795. [2015/12/03 21:03:04 | 000,003,828 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore
  796. [2015/12/03 21:03:04 | 000,004,064 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA
  797. [2015/11/27 23:27:14 | 000,003,834 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Opera scheduled Autoupdate 1448674030
  798. [2015/12/03 21:10:28 | 000,003,598 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Optimize Start Menu Cache Files-S-1-5-21-3925143147-219686701-2106125166-1001
  799. [2015/10/01 15:55:36 | 000,003,168 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\SmartDefrag3_Update
  800. [2015/12/03 20:51:46 | 000,003,958 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{B042639D-D4CF-4897-BF85-959BAAF984ED}
  801. [2015/12/03 14:54:12 | 000,003,704 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
  802. [2015/12/03 14:54:05 | 000,003,710 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
  803. [2015/11/11 16:16:17 | 000,003,476 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
  804. [2015/11/11 16:16:17 | 000,003,470 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
  805. [2013/08/22 13:37:37 | 000,004,472 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
  806. [2013/08/22 13:37:37 | 000,003,854 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
  807. [2013/08/22 13:38:14 | 000,002,900 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\AppID\PolicyConverter
  808. [2013/08/22 13:38:32 | 000,003,558 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\AppID\SmartScreenSpecific
  809. [2013/08/22 13:38:14 | 000,003,790 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
  810. [2013/08/22 13:37:55 | 000,002,902 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Application Experience\AitAgent
  811. [2015/10/15 21:24:51 | 000,004,170 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
  812. [2015/10/15 17:19:11 | 000,002,838 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater
  813. [2013/08/22 13:38:31 | 000,003,154 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Application Experience\StartupAppTask
  814. [2013/08/22 13:38:48 | 000,002,814 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState
  815. [2015/09/18 17:40:08 | 000,003,640 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
  816. [2013/08/22 13:37:41 | 000,003,022 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Autochk\Proxy
  817. [2013/08/22 13:38:52 | 000,002,118 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask
  818. [2013/08/22 13:37:21 | 000,004,130 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\CertificateServicesClient\SystemTask
  819. [2013/08/22 13:37:21 | 000,003,868 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\CertificateServicesClient\UserTask
  820. [2015/09/18 16:40:18 | 000,003,134 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\CertificateServicesClient\UserTask-Roam
  821. [2013/08/22 13:38:56 | 000,003,028 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Chkdsk\ProactiveScan
  822. [2013/08/22 13:38:51 | 000,003,178 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM
  823. [2013/08/22 13:38:17 | 000,002,934 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator
  824. [2013/08/22 13:37:48 | 000,003,316 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
  825. [2015/12/03 14:46:19 | 000,003,516 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader
  826. [2013/08/22 13:37:57 | 000,003,182 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
  827. [2013/08/22 13:39:01 | 000,004,450 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
  828. [2013/08/22 13:39:01 | 000,004,012 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
  829. [2013/08/22 13:38:31 | 000,003,266 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Defrag\ScheduledDefrag
  830. [2015/12/03 22:58:32 | 000,003,782 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Device Setup\Metadata Refresh
  831. [2013/08/22 13:38:35 | 000,003,170 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Diagnosis\Scheduled
  832. [2015/09/21 20:59:13 | 000,003,696 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup
  833. [2015/10/02 14:35:48 | 000,003,120 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
  834. [2015/10/09 17:44:50 | 000,002,538 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
  835. [2015/09/21 20:59:21 | 000,002,618 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\DiskFootprint\Diagnostics
  836. [2013/08/22 21:00:01 | 000,003,696 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync
  837. [2013/08/22 13:38:55 | 000,003,834 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\FileHistory\File History (maintenance mode)
  838. [2013/08/22 13:37:35 | 000,003,630 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\IME\SQM data sender
  839. [2013/08/22 13:39:02 | 000,003,554 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Location\Notifications
  840. [2013/08/22 13:37:37 | 000,003,178 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Maintenance\WinSAT
  841. [2013/08/22 13:38:51 | 000,006,054 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
  842. [2013/08/22 13:38:51 | 000,003,640 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
  843. [2013/08/22 13:38:48 | 000,004,410 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser
  844. [2013/08/22 13:38:11 | 000,003,030 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\MUI\LPRemove
  845. [2013/08/22 13:38:42 | 000,002,602 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Multimedia\SystemSoundsService
  846. [2013/08/22 13:37:17 | 000,002,738 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
  847. [2013/08/22 13:38:14 | 000,002,044 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo
  848. [2013/08/22 21:00:02 | 000,003,136 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Offline Files\Background Synchronization
  849. [2013/08/22 21:00:02 | 000,002,736 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Offline Files\Logon Synchronization
  850. [2015/09/20 15:10:02 | 000,004,084 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor
  851. [2013/08/22 13:38:56 | 000,002,980 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\PI\Secure-Boot-Update
  852. [2013/08/22 13:38:56 | 000,002,872 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\PI\Sqm-Tasks
  853. [2013/08/22 13:38:58 | 000,003,590 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy
  854. [2013/08/22 13:37:16 | 000,003,200 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required
  855. [2013/08/22 13:38:57 | 000,003,562 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
  856. [2013/08/22 13:37:49 | 000,002,128 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers
  857. [2013/08/22 13:38:41 | 000,003,162 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
  858. [2013/08/22 13:38:36 | 000,005,624 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\RAC\RacTask
  859. [2013/08/22 13:37:43 | 000,003,248 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Ras\MobilityManager
  860. [2015/10/02 14:35:53 | 000,003,750 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
  861. [2013/08/22 13:38:14 | 000,003,326 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Registry\RegIdleBackup
  862. [2013/08/22 13:38:57 | 000,004,596 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
  863. [2015/12/03 20:17:16 | 000,003,544 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\RemovalTools\MRT_HB
  864. [2013/08/22 13:38:47 | 000,002,944 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Servicing\StartComponentCleanup
  865. [2013/08/22 13:39:00 | 000,003,360 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask
  866. [2013/08/22 13:39:00 | 000,003,364 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SettingSync\BackupTask
  867. [2013/08/22 13:39:00 | 000,003,462 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
  868. [2015/09/22 19:21:29 | 000,003,176 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess
  869. [2015/09/22 19:21:29 | 000,003,050 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig
  870. [2015/09/22 19:21:29 | 000,003,664 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent
  871. [2015/09/22 19:21:29 | 000,002,876 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent
  872. [2015/12/03 21:34:22 | 000,003,070 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-5d
  873. [2015/12/03 21:34:22 | 000,003,218 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d
  874. [2015/12/03 21:34:22 | 000,003,010 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d
  875. [2015/12/03 21:34:22 | 000,003,558 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d
  876. [2015/12/03 21:34:22 | 000,003,964 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B
  877. [2015/12/03 21:34:22 | 000,003,728 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd
  878. [2015/12/03 21:34:22 | 000,003,394 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Setup\GWXTriggers\Time-5d
  879. [2013/08/22 13:37:23 | 000,002,236 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Shell\CreateObjectTask
  880. [2013/08/22 13:38:57 | 000,002,330 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor
  881. [2015/09/22 19:21:28 | 000,003,216 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Shell\FamilySafetyRefresh
  882. [2015/09/22 19:21:28 | 000,003,014 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Shell\FamilySafetyUpload
  883. [2013/08/22 13:37:27 | 000,003,512 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance
  884. [2013/08/22 13:39:06 | 000,003,036 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
  885. [2013/08/22 13:39:06 | 000,002,768 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
  886. [2015/12/03 22:56:48 | 000,004,680 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
  887. [2015/10/21 23:59:58 | 000,003,840 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
  888. [2015/10/21 23:59:58 | 000,004,478 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
  889. [2013/08/22 13:38:38 | 000,003,590 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask
  890. [2013/08/22 13:37:37 | 000,003,214 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
  891. [2013/08/22 13:37:37 | 000,003,284 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
  892. [2015/09/19 15:15:10 | 000,003,858 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask
  893. [2013/08/22 13:38:48 | 000,002,798 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\SystemRestore\SR
  894. [2013/08/22 13:37:32 | 000,002,614 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Task Manager\Interactive
  895. [2015/12/03 20:17:16 | 000,004,028 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance
  896. [2013/08/22 13:38:35 | 000,004,166 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator
  897. [2013/08/22 13:38:35 | 000,003,048 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance
  898. [2015/11/25 00:43:39 | 000,004,472 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance
  899. [2013/08/22 13:37:53 | 000,002,978 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\TextServicesFramework\MsCtfMonitor
  900. [2013/08/22 13:38:35 | 000,002,848 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
  901. [2013/08/22 13:37:21 | 000,002,918 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime
  902. [2013/08/22 13:39:01 | 000,003,180 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone
  903. [2013/08/22 13:38:56 | 000,004,194 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\TPM\Tpm-Maintenance
  904. [2013/08/22 13:37:18 | 000,001,986 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\UPnP\UPnPHostConfig
  905. [2013/08/22 13:37:49 | 000,003,420 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\User Profile Service\HiveUploadTask
  906. [2013/08/22 13:37:17 | 000,002,682 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WDI\ResolutionHost
  907. [2013/08/22 13:37:17 | 000,004,004 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting
  908. [2013/08/22 13:37:25 | 000,003,290 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
  909. [2013/08/22 13:38:32 | 000,003,304 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary
  910. [2013/08/22 12:47:31 | 000,003,532 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
  911. [2015/09/22 19:21:22 | 000,003,676 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
  912. [2015/12/03 21:36:43 | 000,003,402 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall
  913. [2015/12/03 21:36:43 | 000,005,004 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect
  914. [2015/12/03 21:36:43 | 000,004,926 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start
  915. [2015/12/03 21:36:43 | 000,004,924 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network
  916. [2013/08/22 13:37:24 | 000,003,344 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Wininet\CacheTask
  917. [2015/09/21 20:59:19 | 000,003,448 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WOF\WIM-Hash-Management
  918. [2015/09/22 15:47:12 | 000,003,016 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
  919. [2013/08/22 13:38:47 | 000,002,808 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
  920. [2013/08/22 13:38:47 | 000,003,132 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
  921. [2013/08/22 13:38:51 | 000,003,530 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join
  922. [2013/08/22 13:39:06 | 000,003,606 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WS\Badge Update
  923. [2015/12/03 14:53:56 | 000,005,070 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WS\License Validation
  924. [2013/08/22 13:39:06 | 000,003,464 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WS\Sync Licenses
  925. [2013/08/22 13:39:06 | 000,003,826 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask
  926. [2013/08/22 13:38:32 | 000,003,700 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\Microsoft\Windows\WS\WSTask
  927. [2015/09/20 15:09:57 | 000,004,392 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask
  928. [2015/09/18 16:41:12 | 000,004,484 | ---- | M] () -- C:\WINDOWS\SysNative\tasks\WPD\SqmUpload_S-1-5-21-3925143147-219686701-2106125166-1001
  929.  
  930. [color=#A23BEC]< %windir%\tasks\*.* /s >[/color]
  931. [2015/12/03 22:44:00 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
  932. [2015/12/03 21:08:00 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
  933. [2015/12/03 22:08:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
  934. [2015/12/02 19:25:42 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
  935.  
  936. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement