Forums

  1. Linha Defensiva

    1. Novidades e Avisos

      Novidades do site e avisos da administração do fórum.

      481
      posts
    2. Informações do Fórum

      Regras, informações e FAQs sobre o fórum.

      15
      posts
    3. Boletim Linha Defensiva

      Arquivos do Boletim.

      34
      posts
    4. Comentários, críticas e sugestões

      Se você tem dúvidas, comentários, críticas, elogios ou sugestões sobre o site ou fórum, você pode postar aqui.

      4,040
      posts
  2. Serviços

    1. Remoção de Malware

      Ajuda para a remoção de vírus, worms, trojans e spyware.
      Leia os tópicos destacados dentro do fórum antes de postar!

      292,628
      posts
    2. Experiências Online

      Divida suas experiências online em lojas e outros prestadores de serviço na web. Observe atentamente as regras antes de postar.
      [Pré-moderado+]

      82
      posts
    3. BankerFix

      Dúvidas, tópicos e problemas com a ferramenta de remoção de Bankers BankerFix

      2,802
      posts
    4. ARIS-LD

      Use este fórum para fazer denúncias de links ou arquivos maliciosos ao ARIS, o time de Análise e Resposta a Incidentes de Segurança da Linha Defensiva.

      78
      posts
  3. Malware

    1. Informações e FAQs

      Tutoriais e informações sobre novos spywares, trojans e vírus.
      Somente leitura

      24
      posts
    2. Dúvidas sobre Malware

      Outras dúvidas sobre malware (vírus, trojans, worms, etc)
      Não coloque tópicos para remoção de malware aqui

      19,188
      posts
  4. Segurança

    1. Alertas de Segurança

      Novo vírus à solta? É aqui que você pode avisar sobre ele e ficar sabendo de outros acontecimentos da segurança na Internet.
      [Pré-moderado]

      4,098
      posts
    2. Segurança Geral

      Discuta sobre utilitários de segurança, métodos de proteção e outras dúvidas sobre segurança que não sejam sobre os assuntos dos fóruns acima.

      7,731
      posts
    3. Programas e soluções de backup

      Dicas e dúvidas sobre programas de backup, gerenciamento de mídias e catálogos, soluções de software e hardware para criação de cópias de segurança.

      688
      posts
    4. Redes

      Segurança em redes, redes sem fio, utilização de proxies seguros, proxies e configurações que podem ajudar uma rede, seus clientes e servidores a estarem livre de perigos.

      11,507
      posts
    5. Antivírus

      Problemas e dúvidas sobre antivírus

      14,327
      posts
    6. Anti-Spywares

      Dúvidas e tutorials para Anti-Spywares (Ad-Aware, Spybot, etc).

      5,212
      posts
    7. Firewalls e Filtros

      Dúvidas e tutoriais sobre software e hardware firewalls, proxies e filtros de conteúdo.

      4,328
      posts
    8. Privacidade

      Discussão sobre privacidade e softwares relacionados a privacidade.

      1,529
      posts
  5. Computação Geral

    1. 29,144
      posts
    2. 35,727
      posts
    3. Navegadores & Websites

      Discussão sobre navegadores e clientes FTP, incluindo problemas com websites e curiosidades na web.

      10,890
      posts
    4. Programas de e-mail e anti-spam

      Dúvidas sobre serviços e clientes de e-mail e lixo eletrônico. Questões sobre protocolos de e-mail (POP, IMAP, SMTP) e técnicas anti-spam podem ser colocadas aqui.

      2,300
      posts
    5. Software Geral & Internet

      Ajuda com outros softwares, como Office, utilitários, ferramentas e softwares de Internet como programas P2P, comunicadores instantâneos e outros. Dúvidas sobre navegadores devem ser colocadas no fórum Navegadores & Websites

      18,808
      posts
    6. Discussão e Dúvidas Gerais

      Fórum para dúvidas sobre computação que não estão incluídas nos outros fóruns.

      12,400
      posts
    7. Programação

      Discussão geral sobre programação (C/C++/C#, Delphi, Java, Ruby, Python, etc)

      1,169
      posts
  6. Geral & Entretenimento

    1. Jogos

      Discussão e dúvidas sobre jogos. Emuladores, consoles, lançamentos e dúvidas.

      2,386
      posts
    2. Deskmod

      Tire dúvidas sobre a personalização do seu desktop! Conheça ferramentas e troque idéias para ter uma área de trabalho mais eficiente e bonita.

      696
      posts
    3. Livros, HQs e Mangás

      Fórum para troca de opiniões, resenhas e discussões sobre livros, histórias em quadrinhos e mangás.

      227
      posts
    4. Filmes, séries, animes e músicas

      Fórum para discutir e comentar shows de TV, filmes, seriados, músicas e desenhos animados.

      912
      posts
    5. Casemod

      Discussão, dicas, tutoriais e dúvidas sobre casemod.

      89
      posts
    6. Celulares, câmeras e tablets

      Troque idéias, opiniões e experiências sobre telefones móveis, câmeras fotográficas e eletrônicos de consumo (tablets, TVs, DVD players, etc)

      1,110
      posts
  7. Outros

    1. Notícias da Linha Defensiva

      Notícias publicadas pela Linha Defensiva.

      91
      posts
    2. Notícias

      Notícias gerais sobre o mundo e sobre tecnologia da informação.
      [Pré-moderado] [sCP]

      2,945
      posts
    3. Enquetes

      Para postar suas enquetes.
      [Pré-moderado] [sCP]

      2,004
      posts
    4. Mesa Redonda

      Discussões sobre qualquer tema, da política à religião. Enquetes sobre assuntos que não se enquadram na área de tecnologia também podem ser postadas aqui.
      [Pré-moderado] [sCP]

      1,926
      posts
  • Who's Online   0 Members, 0 Anonymous, 63 Guests (See full list)

    There are no registered users currently online

  • Member Statistics

    122,538
    Total Members
    820
    Most Online
    Dionysio
    Newest Member
    Dionysio
    Joined
  • Recent Status Updates

    • Rangel de Jesus

      Ainda estou com o mesmo problema. Já ajudaram a mim, mas nem no google encontrei solução. Se alguém ai possuir uma luz agradecerei muito. Entrei em contato com o suporte Google também, mas nada de resposta até agora, então, resolvi apelar mais uma vez. Um abraço.
      · 0 replies
    • Ana Paula Vieira

      Boa tarde,
      Estou desesperada, meu netbook está muitooo lento. Além disso, abre páginas da Internet 12334...
      Desliga sozinho, informando que houve um erro no sistema. E agora não estou conseguindo acessar a Internet porque dá erro de certificado da página, mesmo a hora e a data estando corretas. O antivírus acusa que uma ameaça foi detectada, mas mesmo escaneando não consigo resolver e nem atualizar para o Windows 10. Por favor, me ajudem!!!
      · 0 replies
    • Ciro-Mota

      “A noite chega, e agora começa a minha vigia. Não terminará até a minha morte. Não tomarei esposa, não possuirei terras, não gerarei filhos. Não usarei coroas e não conquistarei glórias. Viverei e morrerei no meu posto. Sou a espada na escuridão. Sou o vigilante nas muralhas. Sou o fogo que arde contra o frio, a luz que traz consigo a alvorada, a trombeta que acorda os que dormem, o escudo que defende os reinos dos homens. Dou a minha vida e a minha honra à Patrulha da Noite, por esta noite e...
      · 0 replies
    • Jayzon

      rencontre internet gratuit
      · 0 replies
    • deuler

      Pessoas de sucesso são pessoas comuns com uma determinação extraordinária
      · 0 replies
    • mpvpaiva  »  Sam Spade

      Sam Spade, não sei se minha mensagem foi para você. Meu tópico foi arquivado por eu não ter respondido no prazo, foi porque estou com muitos problemas no notebook e na rede e não conseguia postar os logs. Por favor, reabra meu tópico que já tenho os logs para postar: http://www.linhadefensiva.org/forum/topic/167178-não-consigo-mais-entrar-no-internet-banking-da-caixa-e-o-site-está-estranho/
      · 0 replies
    • Damguimarães

      "A pressa é inimiga da conexão"
      · 2 replies
  • "Censo" de antivírus da Linha Defensiva   32 members have voted

    1. 1. Seu antivírus é pago ou gratuito?


      • Gratuito
      • Pago
    2. 2. Qual antivírus você usa?


      • AVG
      • Avast
      • Avira
      • Baidu
      • BitDefender
      • ESET
      • Kaspersky
      • MalwareBytes
      • McAfee
      • Panda
      • PSafe/Qihoo 360
      • Sophos
      • Symantec/Norton
      • Trend Micro
      • Windows Defender
      • Outro software não listado

    Please sign in or register to vote in this poll. View topic
  • Últimos posts

    • Segue em anexo um novo log da Za-Scan, desde já agradeço a atenção.  ZA-Scan - 2.txt
    • Ciro, LOGs: # AdwCleaner v6.010 - Relatório criado 28/08/2016 às 04:29:02
      # *Updated on 12/08/2016 by ToolsLib
      # Banco de dados : 2016-08-27.1 [Servidor]
      # Sistema operacional : Windows 8.1 Single Language  (X64)
      # Usuário : RODRIGO - CASA
      # Executando de : C:\Users\USER\Desktop\adwcleaner_6.010.exe
      # Limpar
      # Apoio : https://toolslib.net/forum ***** [ Serviços ] ***** [-] Políticas do IE excluídasvToolbarUpdater40.3.2
      [-] Políticas do IE excluídasPanService
      [-] Políticas do IE excluídasWtuSystemSupport
      [-] Políticas do IE excluídasziphost
      ***** [ Pastas ] ***** [-] RestauradoC:\ProgramData\234673bd00004af2
      [-] RestauradoC:\ProgramData\Rloohrutevro
      [#] *Folder deleted on reboot: C:\ProgramData\Application Data\Rloohrutevro
      [-] RestauradoC:\Users\USER\AppData\Local\globalUpdate
      [-] RestauradoC:\Users\USER\AppData\Local\SmartWeb
      [-] RestauradoC:\Users\USER\AppData\Local\avg web tuneup
      [-] RestauradoC:\Users\USER\AppData\LocalLow\Speedbit
      [-] RestauradoC:\Users\USER\AppData\Roaming\cpuminer
      [-] RestauradoC:\Users\USER\AppData\Roaming\ntsvc
      [-] RestauradoC:\Users\USER\AppData\Roaming\Speedbit
      [-] RestauradoC:\Users\USER\AppData\Roaming\Systweak
      [-] RestauradoC:\Users\USER\AppData\Roaming\WinNetSvc
      [-] RestauradoC:\Users\USER\AppData\Roaming\Kuaizip
      [#] *Folder deleted on reboot: C:\Users\USER\AppData\Roaming\KuaiZip
      [-] RestauradoC:\Users\USER\AppData\Roaming\Softlink
      [-] RestauradoC:\Users\USER\AppData\Roaming\PRO PC Cleaner
      [-] RestauradoC:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
      [-] RestauradoC:\Users\USER\Documents\Mobogenie
      [-] RestauradoC:\Program Files\avg web tuneup
      [-] RestauradoC:\Program Files\Common Files\AVG Secure Search
      [-] RestauradoC:\ProgramData\Speedbit
      [-] RestauradoC:\ProgramData\Trymedia
      [-] RestauradoC:\ProgramData\WindowsMsg
      [-] RestauradoC:\ProgramData\avg web tuneup
      [#] *Folder deleted on reboot: C:\ProgramData\Application Data\Speedbit
      [#] *Folder deleted on reboot: C:\ProgramData\Application Data\Trymedia
      [#] *Folder deleted on reboot: C:\ProgramData\Application Data\WindowsMsg
      [#] *Folder deleted on reboot: C:\ProgramData\Application Data\avg web tuneup
      [-] RestauradoC:\ProgramData\Microsoft\Windows\Start Menu\Programs\ttwifi
      [-] RestauradoC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Compress
      [-] RestauradoC:\Users\Public\Documents\Guid
      [-] RestauradoC:\Users\Public\Documents\pc faster
      [-] RestauradoC:\Program Files (x86)\DAP
      [-] RestauradoC:\Program Files (x86)\globalUpdate
      [-] RestauradoC:\Program Files (x86)\PANDORA.TV
      [-] RestauradoC:\Program Files (x86)\avg web tuneup
      [-] RestauradoC:\Program Files (x86)\Common Files\AVG Secure Search
      [-] RestauradoC:\Users\USER\AppData\Local\Temp\Macwebtoise
      [-] RestauradoC:\Users\USER\AppData\Local\Temp\MPC
      [-] RestauradoC:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\ntsvc
      [-] RestauradoC:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Systweak
      [-] RestauradoC:\Users\USER\AppData\Local\app
      [-] RestauradoC:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\extensions\{15e67a59-bd3d-49ae-90dd-b3d3fd14c2ed}
      [-] RestauradoC:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
      [-] RestauradoC:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
      ***** [ Arquivos ] ***** [-] RestauradoC:\Users\USER\daemonprocess.txt
      [-] RestauradoC:\Users\USER\AppData\Roaming\fastboot.exe
      [-] RestauradoC:\Users\USER\AppData\Roaming\adb.exe
      [-] RestauradoC:\Users\USER\AppData\Roaming\a.bat
      [-] RestauradoC:\Users\USER\AppData\Roaming\xdo.zip
      [-] RestauradoC:\Users\USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MaohaWiFi.lnk
      [-] RestauradoC:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk
      [-] RestauradoC:\WINDOWS\SysNative\drivers\KuaiZipDrive.sys
      [-] RestauradoC:\END
      [-] RestauradoC:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\extensions\7go@7go.com.xpi
      [-] RestauradoC:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\extensions\Avg@toolbar.xpi
      [-] RestauradoC:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\extensions\zulagames@ZulaGames.com.xpi
      [-] RestauradoC:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\invalidprefs.js
      [-] RestauradoC:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\searchplugins\avg-secure-search.xml
      [-] RestauradoC:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
      [-] RestauradoC:\Program Files (x86)\Mozilla Firefox\cfg
      [-] RestauradoC:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\zingload.xml
      [#] RestauradoC:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
      [#] RestauradoC:\Program Files (x86)\Mozilla Firefox\cfg
      [#] RestauradoC:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\zingload.xml
      [#] RestauradoC:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
      [#] RestauradoC:\Program Files (x86)\Mozilla Firefox\cfg
      [#] RestauradoC:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\zingload.xml
      [-] RestauradoC:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 2\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage
      [-] RestauradoC:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 2\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal
      ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Atalhos ] ***** ***** [ Tarefas agendadas ] ***** ***** [ Registro ] ***** [-] RestauradoHKCU\Software\5c4dfdfe66de544
      [-] RestauradoHKLM\SOFTWARE\049c152b-dd93-378f-c108-4ae4468a4809
      [-] RestauradoHKLM\SOFTWARE\5c4dfdfe66de544
      [-] RestauradoHKLM\SOFTWARE\Classes\7Go Games.BackgroundHostObject
      [-] RestauradoHKLM\SOFTWARE\Classes\7Go Games.BackgroundHostObject.1
      [-] RestauradoHKLM\SOFTWARE\Classes\7Go Games.Navbar
      [-] RestauradoHKLM\SOFTWARE\Classes\7Go Games.Navbar.1
      [-] RestauradoHKLM\SOFTWARE\Classes\7Go Games.Tool
      [-] RestauradoHKLM\SOFTWARE\Classes\7Go Games.Tool.1
      [-] RestauradoHKLM\SOFTWARE\Classes\AniGIFCtrl.AniGIF
      [-] RestauradoHKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg
      [-] RestauradoHKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg.1
      [-] RestauradoHKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2
      [-] RestauradoHKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2.1
      [-] RestauradoHKLM\SOFTWARE\Classes\Prod.cap
      [-] RestauradoHKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
      [-] RestauradoHKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
      [-] RestauradoHKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
      [-] RestauradoHKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
      [-] RestauradoHKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
      [-] RestauradoHKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
      [-] RestauradoHKLM\SOFTWARE\Classes\Speed Analysis 2.Tool
      [-] RestauradoHKLM\SOFTWARE\Classes\Speed Analysis 2.Tool.1
      [-] RestauradoHKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
      [-] RestauradoHKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.001
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.002
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.003
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.004
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.005
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.006
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.007
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.008
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.009
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.01
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.010
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.011
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.012
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.013
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.014
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.015
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.016
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.017
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.018
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.019
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.02
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.020
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.021
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.022
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.023
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.024
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.025
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.026
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.027
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.028
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.029
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.03
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.030
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.031
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.032
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.033
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.034
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.035
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.036
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.037
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.038
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.039
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.04
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.040
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.041
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.042
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.043
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.044
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.045
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.046
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.047
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.048
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.049
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.05
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.050
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.051
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.052
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.053
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.054
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.055
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.056
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.057
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.058
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.059
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.06
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.060
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.061
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.062
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.063
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.064
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.065
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.066
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.067
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.068
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.069
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.07
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.070
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.071
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.072
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.073
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.074
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.075
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.076
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.077
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.078
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.079
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.08
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.080
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.081
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.082
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.083
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.084
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.085
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.086
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.087
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.088
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.089
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.09
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.090
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.091
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.092
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.093
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.094
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.095
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.096
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.097
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.098
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.099
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.7z
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.arj
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.bz2
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.cab
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.gz
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.gzip
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.iso
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.jar
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.lzh
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.rar
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.rpm
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.tar
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.tbz
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.tgz
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.wim
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.z
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool.zip
      [-] RestauradoHKLM\SOFTWARE\Classes\ZipTool_FileAsso.Origin
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\CLSID\{B33BD6CF-BF4C-4CF0-AC84-B2974BC14ABD}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
      [-] Restaurado[x64] HKLM\SOFTWARE\Classes\Interface\{94952EC4-DB66-3F32-BE4C-F0BB875EA98E}
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
      [-] RestauradoHKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
      [-] RestauradoHKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
      [-] RestauradoHKCU\Software\Classes\CLSID\{E4B02201-EA08-35F8-DE8D-19BB02BBFA9D}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{B33BD6CF-BF4C-4CF0-AC84-B2974BC14ABD}
      [-] RestauradoHKLM\SOFTWARE\Classes\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{066D89E6-B457-4A57-888A-B0AEB11D5BF1}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{0E8990F4-2FC9-403C-883B-535D6271E740}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{1644E2E1-E15E-4E9E-9B25-5668536DD6A7}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{2BA83048-8B7C-4186-843B-D97FC1A6AE95}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{469960F8-8172-4386-BBB1-DF3590027D58}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{753C5ED0-B9AB-4F1E-8DAC-668E701CA569}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{80995911-5CF2-483F-A260-C736E8D0C691}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{821ED2B3-866E-4177-870E-52D995D123D0}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{9B4E4BF6-9346-4969-8428-C3CB81CD7A30}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{9BAC5A3B-33FD-4DB9-A4F1-B749498D4017}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{A6670033-7A4B-4F59-B8A9-A7CEBF3CE960}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{B1285825-F24F-4651-9F8A-2012460AD2FC}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{B3D38AE9-C808-4811-8417-F114839D6392}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{B8E64931-27EF-42BC-AF3B-0E2B25D17567}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{BE952BDF-6FDF-4A62-B318-E15D4487A2EF}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{C0233F6C-3110-4AEA-A798-C81DA43CED9E}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{CC5B7648-AAF8-4642-B53D-B7B5E4AE7241}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{D325B617-D6F9-4C72-90B2-A38E6D15C16E}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{DF51AD29-5239-441A-B921-E655C8162060}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{E515494B-7548-462A-B7E7-A3E6F8C4899C}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{E9ECFFF9-2011-439F-92EB-BE145ACD87DA}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{FBB92627-0DAA-4B69-97CC-9879236FE039}
      [-] RestauradoHKLM\SOFTWARE\Classes\Interface\{94952EC4-DB66-3F32-BE4C-F0BB875EA98E}
      [-] RestauradoHKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
      [-] RestauradoHKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
      [-] RestauradoHKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
      [-] RestauradoHKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
      [-] RestauradoHKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
      [-] RestauradoHKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] RestauradoHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] RestauradoHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{EA34C851-D481-49F5-A356-3A8B0A8F3B7E}]
      [-] Restaurado[x64] HKLM\SOFTWARE\searchult
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gpuminer
      [-] RestauradoHKU\.DEFAULT\Software\Browser
      [-] RestauradoHKU\.DEFAULT\Software\KuaiZip
      [-] RestauradoHKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
      [-] RestauradoHKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer
      [-] RestauradoHKU\S-1-5-19\Software\Browser
      [-] RestauradoHKU\S-1-5-20\Software\Browser
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\APN PIP
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Browser
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\FastCompress-Zip
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\GlobalUpdate
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Kromtech
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Linkey
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Popajar
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Reg\Clean
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\simplytech
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Softonic
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\SpeedBit
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\USyndication
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\usyndication.com
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\osTip
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\ttwifi
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\AutoTime
      [#] *Key deleted on reboot: HKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\SIMPLYTECH
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\KuaiZip
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\SNDA
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\KuaiZipSFX
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\ZipTool
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Maoha
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Iminent
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Speed Analysis 2
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-228857345-1929742360-2452464294-1001\Software\SpeedBit
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-228857345-1929742360-2452464294-1001\Software\SweetIM
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer
      [#] *Key deleted on reboot: HKU\S-1-5-18\Software\Browser
      [#] *Key deleted on reboot: HKU\S-1-5-18\Software\KuaiZip
      [#] *Key deleted on reboot: HKU\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
      [#] *Key deleted on reboot: HKU\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer
      [#] *Key deleted on reboot: HKCU\Software\APN PIP
      [#] *Key deleted on reboot: HKCU\Software\Browser
      [#] *Key deleted on reboot: HKCU\Software\FastCompress-Zip
      [#] *Key deleted on reboot: HKCU\Software\GlobalUpdate
      [#] *Key deleted on reboot: HKCU\Software\Kromtech
      [#] *Key deleted on reboot: HKCU\Software\Linkey
      [#] *Key deleted on reboot: HKCU\Software\Popajar
      [#] *Key deleted on reboot: HKCU\Software\Reg\Clean
      [#] *Key deleted on reboot: HKCU\Software\simplytech
      [#] *Key deleted on reboot: HKCU\Software\Softonic
      [#] *Key deleted on reboot: HKCU\Software\SpeedBit
      [#] *Key deleted on reboot: HKCU\Software\USyndication
      [#] *Key deleted on reboot: HKCU\Software\usyndication.com
      [#] *Key deleted on reboot: HKCU\Software\osTip
      [#] *Key deleted on reboot: HKCU\Software\ttwifi
      [#] *Key deleted on reboot: HKCU\Software\AutoTime
      [#] *Key deleted on reboot: HKCU\Software\SIMPLYTECH
      [#] *Key deleted on reboot: HKCU\Software\KuaiZip
      [#] *Key deleted on reboot: HKCU\Software\SNDA
      [#] *Key deleted on reboot: HKCU\Software\KuaiZipSFX
      [#] *Key deleted on reboot: HKCU\Software\ZipTool
      [#] *Key deleted on reboot: HKCU\Software\Maoha
      [-] RestauradoHKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
      [-] RestauradoHKLM\SOFTWARE\AIM Toolbar
      [-] RestauradoHKLM\SOFTWARE\Bench
      [-] RestauradoHKLM\SOFTWARE\Conduit
      [-] RestauradoHKLM\SOFTWARE\FastCompress-Zip
      [-] RestauradoHKLM\SOFTWARE\GlobalUpdate
      [-] RestauradoHKLM\SOFTWARE\IGS
      [-] RestauradoHKLM\SOFTWARE\NetTcpHandler
      [-] RestauradoHKLM\SOFTWARE\NtSvcHandler
      [-] RestauradoHKLM\SOFTWARE\PIP
      [-] RestauradoHKLM\SOFTWARE\Reg\Clean
      [-] RestauradoHKLM\SOFTWARE\SearchProtect
      [-] RestauradoHKLM\SOFTWARE\searchult
      [-] RestauradoHKLM\SOFTWARE\SpeedBit
      [-] RestauradoHKLM\SOFTWARE\SupDp
      [-] RestauradoHKLM\SOFTWARE\Trymedia Systems
      [-] RestauradoHKLM\SOFTWARE\AVG Tuneup
      [#] *Key deleted on reboot: HKLM\SOFTWARE\SEARCHPROTECT
      [#] *Key deleted on reboot: HKLM\SOFTWARE\SUPDP
      [-] RestauradoHKLM\SOFTWARE\ZipTool
      [-] RestauradoHKLM\SOFTWARE\Maoha
      [#] *Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{10A0E600-D246-BD63-F465-4C849C688998}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{594FD08C-0622-F9B8-CB02-7C1355D33CB8}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{614925F9-841A-53FE-A28F-DC30FA07239B}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B114619-78B7-1CFF-55EF-74266954F883}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AE9B04F2-E9E8-162C-829B-52C116B3EFCC}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Iminent
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3038A20B9089EC34D8F74220191FAB30
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [#] *Value deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
      [#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
      [-] RestauradoHKLM\SOFTWARE\Classes\Unknown\shell\openas\command [Default]
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\cmptch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\eshopcomp.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\inst.shoppingate.info
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\land.pckeeper.software
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\mystartsearch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\nps.pastaleads.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\pastaleads.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\pckeeper.software
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.eshopcomp.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\reimageplus.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\shoppingate.info
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.mystartsearch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\a2g-secure.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bestpriceninja.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\contextualyield.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\eshopcomp.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\foxi69.tlscdn.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inst.shoppingate.info
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystartsearch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nps.pastaleads.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pastaleads.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.bestpriceninja.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.eshopcomp.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\reimageplus.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\shoppingate.info
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.cmptch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\televisionfanatic.dl.tb.ask.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tlscdn.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.mystartsearch.com
      [-] RestauradoHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [3D BubbleSound]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [cpuminer]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gpuminer]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [gpuminer]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [mobilegeni daemon]
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
      [-] RestauradoHKU\S-1-5-21-228857345-1929742360-2452464294-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Optimizer Pro]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [SmartWeb]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [vProt]
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [WinCheck]
      [-] Restaurado[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Windesk Winsearch]
      [-] RestauradoHKLM\SOFTWARE\Classes\AppID\escortApp.DLL
      [-] RestauradoHKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
      [-] RestauradoHKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
      [-] RestauradoHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia
      [-] RestauradoHKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\FastCompress-Zip
      [-] RestauradoHKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\FastCompress-Zip
      [-] RestauradoHKLM\SOFTWARE\Classes\Drive\shellex\DragDropHandlers\FastCompress-Zip
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\FM.exe
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
      [-] RestauradoHKLM\SOFTWARE\Classes\s
      [-] RestauradoHKLM\SOFTWARE\Classes\AppID\jZipShell.DLL
      [-] RestauradoHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [kuaizipupdatesvc]
      [-] RestauradoHKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\JZipShlExt
      [-] RestauradoHKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\JZipShlExt
      [-] RestauradoHKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\KuaiZipShlExt
      [-] RestauradoHKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\KuaiZipShlExt
      [-] RestauradoHKLM\SOFTWARE\Mozilla\Firefox\Extensions [daplinkchecker@speedbit.com]
      [#] *Value deleted on reboot: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [daplinkchecker@speedbit.com]
      [#] *Value deleted on reboot: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [daplinkchecker@speedbit.com]
      [-] RestauradoHKLM\SOFTWARE\Google\Chrome\Extensions\lkemddiljapcmhicklfpcbpfffahfbja
      [-] RestauradoHKCU\Software\Google\Chrome\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
      ***** [ Navegadores ] ***** [-] Chrome preferences reset"browser.search.defaultenginename" -  "Yahoo! Powered"
      [-] Chrome preferences reset"browser.search.selectedEngine" -  "Yahoo! Powered"
      [-] Chrome preferences reset"extensions.installCache" -  "[{\"name\":\"winreg-app-global\",\"addons\":{\"daplinkchecker@speedbit.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\DAP\\\\daplinkchecker\",\"mtime\":1471042260984,\"rdfTime\":1391376182000}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1413065339872,\"rdfTime\":1413065339840}}},{\"name\":\"winreg-app-user\",\"addons\":{\"{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\DAP\\\\DAPFireFox\",\"mtime\":1471042257804,\"rdfTime\":1471042120000}}},{\"name\":\"app-profile\",\"addons\":{\"7go@7go.com\":{\"descriptor\":\"C:\\\\Users\\\\USER\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\hmwemuh4.default\\\\extensions\\\\7go@7go.com.xpi\",\"mtime\":1389237033868},\"avg@toolbar\":{\"descriptor\":\"C:\\\\Users\\\\USER\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\hmwemuh4.default\\\\extensions\\\\avg@toolbar.xpi\",\"mtime\":1470427285872},\"zulagames@ZulaGames.com\":{\"descriptor\":\"C:\\\\Users\\\\USER\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\hmwemuh4.default\\\\extensions\\\\zulagames@ZulaGames.com.xpi\",\"mtime\":1389309159396},\"{15e67a59-bd3d-49ae-90dd-b3d3fd14c2ed}\":{\"descriptor\":\"C:\\\\Users\\\\USER\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\hmwemuh4.default\\\\extensions\\\\{15e67a59-bd3d-49ae-90dd-b3d3fd14c2ed}\",\"mtime\":1469584093059,\"rdfTime\":1431202698152}}}]"
      [-] [C:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 2] [extension] Excluídochfdnecihphmhljaaejmgoiahnihplgn
      [-] [C:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 2] [extension] Excluídolkemddiljapcmhicklfpcbpfffahfbja
      [-] [C:\Users\USER\AppData\Local\Google\Chrome\User Data\Profile 3] [extension] Excluídochfdnecihphmhljaaejmgoiahnihplgn
      ************************* :: Chaves "Tracing" excluídas
      :: Configurações Winsock restauradas ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [47801 *Bytes] - [28/08/2016 04:29:02]
      C:\AdwCleaner\AdwCleaner[S0].txt - [44917 *Bytes] - [28/08/2016 04:23:23] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [47951 *Bytes] ##########
      ______________________________________________________________________________________________________ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Junkware Removal Tool (JRT) by Malwarebytes
      Version: 8.0.7 (07.03.2016)
      Operating System: Windows 8.1 Single Language x64 
      Ran by RODRIGO (Administrator) on 28/08/2016 at  6:27:04,62
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      File System: 10  Successfully deleted: C:\ProgramData\76b17d8bdf6a498aaa93050b412fa968 (Folder) 
      Successfully deleted: C:\ProgramData\alawarwrapper (Folder) 
      Successfully deleted: C:\ProgramData\browser (Folder) 
      Successfully deleted: C:\ProgramData\f06430b2c9f64166a6d66f0570b30c51 (Folder) 
      Successfully deleted: C:\ProgramData\t122078ed (Folder) 
      Successfully deleted: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\user.js (File) 
      Successfully deleted: C:\Users\USER\Documents\add-in express (Folder) 
      Successfully deleted: C:\WINDOWS\wininit.ini (File) 
      Successfully deleted: C:\Users\USER\AppData\Roaming\appdataFr25.bin (File) 
      Successfully deleted: C:\Users\USER\AppData\Roaming\appdataFr3.bin (File)  Registry: 2  Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} (Registry Key)
      Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} (Registry Key)
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Scan was completed on 28/08/2016 at  6:28:34,23
      End of JRT log
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      ______________________________________________________________________________________ ~ ZHPCleaner v2016.8.25.114 by Nicolas Coolman (2016/08/25)
      ~ Run by RODRIGO (Administrator)  (28/08/2016 06:36:32)
      ~ Web: https://www.nicolascoolman.com
      ~ Blog: https://www.anti-malware.top
      ~ Facebook : https://www.facebook.com/nicolascoolman1
      ~ State version : Version OK
      ~ Type : Reparo
      ~ Report : C:\Users\USER\Desktop\ZHPCleaner.txt
      ~ Quarantine : C:\Users\USER\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
      ~ UAC : Activate
      ~ Boot Mode : Normal (Normal boot)
      Windows 8.1 Single Language, 64-bit  (Build 9600)
      ---\\  Serviços (0)
      ~ Nenhum ítem malicioso o desnecessários foi encontrado.
      ---\\  Navegadores de Internet (0)
      ~ Nenhum ítem malicioso o desnecessários foi encontrado.
      ---\\  Arquivo hosts (0)
      ~ Nenhum ítem malicioso o desnecessários foi encontrado.
      ---\\  Tarefas automáticas agendadas. (2)
      SUPRIMIDO tarefas: [AutoKMS] [C:\WINDOWS\Tasks\AutoKMS.job (Not File) ]  =>HackTool.AutoKMS
      SUPRIMIDO tarefas: [AutoKMSDaily] [C:\WINDOWS\Tasks\AutoKMSDaily.job (Not File) ]  =>HackTool.AutoKMS
      ---\\  Explorer ( Arquivos, Pastas) (12)
      MOVIDO pasta: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\storage\persistent\http+++www.bobrowser.com\.metadata    =>PUP.Optional.BoBrowser
      MOVIDO pasta: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\storage\persistent\http+++www.bobrowser.com\idb\1320802654iedibk_oeovcer.sqlite    =>PUP.Optional.BoBrowser
      MOVIDO pasta: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\storage\persistent\http+++searches.vi-view.com\.metadata    =>PUP.Optional.MyhomeViview
      MOVIDO pasta: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\hmwemuh4.default\storage\persistent\http+++searches.vi-view.com\idb\1320802654iedibk_oeovcer.sqlite    =>PUP.Optional.MyhomeViview
      MOVIDO pasta: C:\Users\USER\AppData\Roaming\ziptool_wc-9015_setup.exe [Copyright (c) 2015 - Compress安装程序]  =>PUP.Optional.Pirrit
      MOVIDO pasta: C:\Windows\Tasks\AutoKMS.job    =>HackTool.AutoKMS
      MOVIDO pasta: C:\Windows\Tasks\AutoKMSDaily.job    =>HackTool.AutoKMS
      MOVIDO pasta: C:\Windows\Prefetch\3D BUBBLESOUND.EXE-A808106B.pf    =>PUP.Optional.BubbleSound
      MOVIDO pasta: C:\Windows\Prefetch\ANYPROTECT.EXE-1996592C.pf    =>PUP.Optional.AnyProtect
      MOVIDO pasta: C:\Windows\Prefetch\J4BLOCKANDSURFJ52.EXE-B5507FAA.pf    =>PUP.Optional.BlockAndSurf
      MOVIDO pasta: C:\Windows\Prefetch\SIGNUP WIZARD.EXE-CEFD4E77.pf    =>PUP.Optional.MyPCBackup
      MOVIDO pasta: C:\WINDOWS\System32\ssm1mci.exe [SS - SSCoInstExe]  =>.Superfluous.SwiftSearch
      ---\\  Registro ( Chaves, Valores, Dados ) (38)
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1B74ED44-08BB-40F1-8CF3-3F2CBB84B1F0} [C:\Program Files (x86)\Speed Analysis 2 (Not File)]  =>PUP.Optional.SpeedAnalysis
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F555EFFC-201A-485C-8BEF-F8F5072A8D34} [C:\Program Files (x86)\Speed Analysis 3 (Not File)]  =>PUP.Optional.SpeedAnalysis
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\anyprotect.com []  =>PUP.Optional.AnyProtect
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdncache-a.akamaihd.net [138]  =>.Superfluous.AkamaiHD
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\d19tqk5t6qcjac.cloudfront.net [337]  =>.Superfluous.CloudfrontNet
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\powerbundle.systweak.com [88]  =>PUP.Optional.SystSupportDock
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\soundcloud.com []  =>PUP.Optional.SoundCloud
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.boostsaves.com []  =>PUP.Optional.BoostSaves
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\systweak.com []  =>PUP.Optional.SystSupportDock
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.anyprotect.com [69]  =>PUP.Optional.AnyProtect
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cdncache-a.akamaihd.net []  =>.Superfluous.AkamaiHD
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d19tqk5t6qcjac.cloudfront.net [321]  =>.Superfluous.CloudfrontNet
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\download.televisionfanatic.com [204]  =>PUP.Optional.TelevisionFanatic
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\eorezo.com []  =>.Superfluous.EORezo
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hdapp1008-a.akamaihd.net [8]  =>.Superfluous.AkamaiHD
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\soundcloud.com []  =>PUP.Optional.SoundCloud
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.boostsaves.com [2336]  =>PUP.Optional.BoostSaves
      SUPRIMIDO chave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\televisionfanatic.com []  =>PUP.Optional.TelevisionFanatic
      SUPRIMIDO chave*: HKCU\Software\undefined []  =>.Superfluous.Downloader
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\77zip.exe []  =>PUP.Optional.InstallBrain
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{0535258B-F87E-4319-9BBF-AF49E7F54B12} [RouyaalCouppOn]  =>PUP.Optional.RoyalCoupon
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{2268FCA5-F2DC-4799-AE25-F3051CDECB8D} [RoyAlCouupOn]  =>PUP.Optional.RoyalCoupon
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{23d89d18-82e1-4899-942d-e80ce1d709bb} [SmAArtCompare]  =>PUP.Optional.SmartCompare
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{35ACE427-169F-473D-9F70-9D072633687C} [LuckyShoppear]  =>PUP.Optional.LuckyShopper
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{966F45C9-544D-4BEF-B53C-6CE5B7778E91} [PriancceCoupon]  =>PUP.Optional.PriceCoupon
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{9e565284-ce43-42b7-9375-943ff1c9f279} [SaverAdidon]  =>PUP.Optional.SaverOn
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{E3E5D18B-3FD3-4C23-84C1-622E1864079B} [FlashCouppoon]  =>PUP.Optional.FlashCoupon
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{FF2BB5B0-3A1A-4793-80B8-70E4B295E362} [LuckySHopppeR]  =>PUP.Optional.LuckyShopper
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\DtsEncodeTools []  =>PUP.Optional.WeatherTool
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 []  =>PUP.Optional.MyPCBackup
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS []  =>PUP.Optional.MyPCBackup
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 []  =>.Superfluous.ByteFence
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS []  =>.Superfluous.ByteFence
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe []  =>PUP.Optional.BonanzaDeals
      SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [ITool]  =>Toolbar.Ask
      SUPRIMIDO valor: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\crossbrowse.lnk [0x0300000064CC842C21DBD101]  =>PUP.Optional.CrossBrowse
      SUPRIMIDO valor: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\MyPC Backup.lnk [0x03000000DB171A6D21DBD101]  =>PUP.Optional.MyPCBackup
      SUPRIMIDO valor: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\SmartWeb.lnk [0x030000005CDBFC8121DBD101]  =>PUP.Optional.SmartWebSearch
      ---\\  Resumo dos elementos encontrados na sua estação de trabalho (31)
      https://www.anti-malware.top/2016/05/04/hacktool-autokms/  =>HackTool.AutoKMS
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.BoBrowser
      https://www.nicolascoolman.com/fr/pup-myhomeviview/  =>PUP.Optional.MyhomeViview
      https://www.nicolascoolman.com/fr/pup-pirritsuggestor/  =>PUP.Optional.Pirrit
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.BubbleSound
      https://www.nicolascoolman.com/fr/pup-anyprotect/  =>PUP.Optional.AnyProtect
      https://www.nicolascoolman.com/fr/pup-blockandsurf/  =>PUP.Optional.BlockAndSurf
      https://www.nicolascoolman.com/fr/pup-mypcbackup/  =>PUP.Optional.MyPCBackup
      https://www.nicolascoolman.com/fr/ppup-optional-swiftsearch/  =>.Superfluous.SwiftSearch
      https://www.nicolascoolman.com/fr/pup-speedanalysis/  =>PUP.Optional.SpeedAnalysis
      https://www.nicolascoolman.com/fr/logiciels-superflus  =>.Superfluous.AkamaiHD
      https://www.nicolascoolman.com/fr/logiciels-superflus  =>.Superfluous.CloudfrontNet
      https://www.nicolascoolman.com/fr/pup-systsupportdock/  =>PUP.Optional.SystSupportDock
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.SoundCloud
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.BoostSaves
      https://www.nicolascoolman.com/fr/pup-televisionfanatic/  =>PUP.Optional.TelevisionFanatic
      https://www.nicolascoolman.com/fr/pup-eorezo/  =>.Superfluous.EORezo
      https://www.nicolascoolman.com/fr/logiciels-superflus  =>.Superfluous.Downloader
      https://www.nicolascoolman.com/fr/adware-installbrain/  =>PUP.Optional.InstallBrain
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.RoyalCoupon
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.SmartCompare
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.LuckyShopper
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.PriceCoupon
      https://www.nicolascoolman.com/fr/pup-saveron/  =>PUP.Optional.SaverOn
      https://www.nicolascoolman.com/fr/repaquetage-et_infections/  =>PUP.Optional.FlashCoupon
      https://www.nicolascoolman.com/fr/pup-optional-weathertool  =>PUP.Optional.WeatherTool
      https://www.anti-malware.top/2016/04/29/superfluous-bytefence/  =>.Superfluous.ByteFence
      https://www.anti-malware.top/2016/04/28/pup-optional-bonanzadeals/  =>PUP.Optional.BonanzaDeals
      https://www.nicolascoolman.com/fr/toolbar-ask/  =>Toolbar.Ask
      https://www.nicolascoolman.com/fr/pup-optional-crossbrowse  =>PUP.Optional.CrossBrowse
      https://www.nicolascoolman.com/fr/pup-smartwebsearch/  =>PUP.Optional.SmartWebSearch
      ---\\  Dodatkowe oczyszczenie. (17)
      ~ Chave de registro Tracing Supprimido (17)
      ~ Remover os relatórios antigos ZHPCleaner. (0)
      ---\\ Resultado de reparação
      Reparação efectuada com sucesso
      ---\\ Estatísticas
      ~ Items scan : 992
      ~ Items encontrado : 0
      ~ items cancelados : 0
      ~ Items réparo : 52
      ~ End of clean in 00h00mn52s
      ~====================
      ZHPCleaner-[R]-28082016-06_37_24.txt
      ZHPCleaner--28082016-06_36_10.txt
          sc-cleaner.txt MBAM.txt
    • Por favor, Preciso de ajuda. Eu tenho uma impressora multifuncional HP Officejet J3680 All-in-one e desde ontem não consigo imprimir colorido, independente do arquivo (PDF,.doc, página da internet...). Não consigo também fazer cópias coloridas. Todas as tentativas ficaram em preto e branco. Já segui as orientações do site da HP, verificando as configurações da impressora, impressão de página teste e alinhamento dos cartuchos. Pensei que pudesse ser problema do cartucho colorido (estava no fim) e troquei por um novo e não adiantou. Inclusive o disposito de "Central de soluções HP" informa que os cartuchos estão cheios. Os cartuchos são originais de fábrica da HP. O que posso fazer??? Alguém poderia me ajudar??? Tenho necessidade de imprimir com urgência uns trabalhos escolares dos meus filhos e são coloridos. Socorro..... 
    • Bom dia Ciro, Nenhum log foi gerado, mas tive que rodar/instalar o programa várias vezes, pois ele começava a atualizar o banco de dados e ai parava com a seguinte mensagem ''Can not get update, is proxy configured?'' na quinta vez desse processo atualizou e escaneou até a metade e parava dizendo que havia sido pedido o término (isso por duas vezes) até que por final fez o scan completo. Apareceu no desktop um arquivo Dump_Hdd0_DR0.mbr, não sei o que é, mas pelo horário foi após o uso do MbrScan, devo manter? Obrigado, Claudia  
    • Feito. Muito obrigado pela ajuda. Apenas mais uma pergunta, se possivel, antes de encerrar o topico: tenho instalados (as versoes gratuitas) Avast, Spyware Terminator 2015 e Advanced SystemCare. (meu Windows é Vista) Os dois ultimos ajdam a protejer o computador ou posso desinstala-los?   Obrigado
    • Bom dia Ciro, Não encontrei a opção scan; tinham 2 opções: examinar... e corrigir. Cliquei em examinar e só, ao final me deu os dois logs que seguem,x     Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 27-08-2016
      Executado por eliete-ma1hotmail.co (administrador) em ELIETE (28-08-2016 00:21:32)
      Executando a partir de C:\Users\eliete-ma1hotmail.co\Desktop
      Perfis Carregados: eliete-ma1hotmail.co (Perfis Disponíveis: eliete-ma1hotmail.co & Administrador)
      Platform: Windows 10 Home Single Language Versão 1511 (X64) Idioma: Português (Brasil)
      Internet Explorer Versão 11 (Navegador padrão: Edge)
      Modo da Inicialização: Normal
      Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
      (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
      (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
      (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
      (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
      (Samsung Electronics Co., Ltd.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
      (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
      (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
      (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe
      (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
      (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
      (SAMSUNG Electronics co., LTD.) C:\ProgramData\Samsung\ShutdownEvent.exe
      (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsCmdServer.exe
      (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsEventHandler.exe
      () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
      (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
      (Intel Corporation) C:\Windows\System32\igfxEM.exe
      (Intel Corporation) C:\Windows\System32\igfxHK.exe
      (Intel Corporation) C:\Windows\System32\igfxext.exe
      (Intel Corporation) C:\Windows\System32\igfxTray.exe
      (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
      (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
      (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
      (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
      (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\nis.exe
      (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\nis.exe
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      (Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
      (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.23941.0_x64__8wekyb3d8bbwe\Video.UI.exe
      (Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
      (Microsoft Corporation) C:\Windows\splwow64.exe
      () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
      ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040296 2015-08-28] (Realtek Semiconductor)
      HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
      HKLM\...\Run: [Bitcasa] => C:\Program Files\Bitcasa\Bitcasa.exe [3965904 2013-06-06] ()
      HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [600928 2014-02-13] (Copyright 2013 SAMSUNG)
      HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3251408 2015-09-23] (ELAN Microelectronics Corp.)
      HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\...\Run: [Chromium] => c:\users\eliete-ma1hotmail.co\appdata\local\chromium\application\chrome.exe [667136 2015-08-11] (The Chromium Authors)
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\...\Run: [DisplaySwitch] => C:\programdata\samsung\DisplaySwitch.exe [1758512 2013-12-10] (TODO: <Company name>)
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\...\RunOnce: [Uninstall C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64"
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\...\RunOnce: [Uninstall C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1"
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\...\RunOnce: [Uninstall C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\...\RunOnce: [Uninstall C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6302.0225] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6302.0225"
      SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
      SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
      ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
      ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
      ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
      ShellIconOverlayIdentifiers: [1EldosIconOverlay] -> {3B57FB6C-A919-4F9F-A547-5338311D45B9} => C:\windows\SYSTEM32\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
      ShellIconOverlayIdentifiers: [BitcasaIconOverlay] -> {A6975448-A999-49BB-B3E4-7730CF6A82C0} => C:\Program Files\Bitcasa\ExplorerMenu.dll [2013-06-06] ()
      ShellIconOverlayIdentifiers: [BitcasaProgressOverlay] -> {6FB8D52A-0064-45B2-B687-F596FEAD09C2} => C:\Program Files\Bitcasa\ExplorerMenu.dll [2013-06-06] ()
      ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\system32\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
      ShellIconOverlayIdentifiers-x32: [1EldosIconOverlay] -> {3B57FB6C-A919-4F9F-A547-5338311D45B9} => C:\windows\SysWOW64\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
      ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\SysWow64\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
      Startup: C:\Users\eliete-ma1hotmail.co\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Enviar para o OneNote.lnk [2016-04-07]
      ShortcutTarget: Enviar para o OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{bb8cdb09-5c1b-4133-8b56-5e7ff5c25bfa}: [DhcpNameServer] 192.168.0.1 Internet Explorer:
      ==================
      HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWVoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=MGpdNGZcMWRd
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWVoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=MGpdNGZcMWRd
      HKU\S-1-5-21-1917681920-812532136-750919602-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com/?pc=smjb
      SearchScopes: HKLM -> DefaultScope {25AEA4C0-6ABA-42AD-8BCD-644EB82536FD} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWJoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=NGVaMGV9NaJ4MZ%3D%3D&p={searchTerms}
      SearchScopes: HKLM -> {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
      SearchScopes: HKLM -> {25AEA4C0-6ABA-42AD-8BCD-644EB82536FD} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWJoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=NGVaMGV9NaJ4MZ%3D%3D&p={searchTerms}
      SearchScopes: HKLM -> {a62abdee-78a2-4ddb-9355-1c334abd6e43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
      SearchScopes: HKLM-x32 -> DefaultScope {25AEA4C0-6ABA-42AD-8BCD-644EB82536FD} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWJoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=NGVaMGV9NaJ4MZ%3D%3D&p={searchTerms}
      SearchScopes: HKLM-x32 -> {25AEA4C0-6ABA-42AD-8BCD-644EB82536FD} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWJoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=NGVaMGV9NaJ4MZ%3D%3D&p={searchTerms}
      SearchScopes: HKLM-x32 -> {a62abdee-78a2-4ddb-9355-1c334abd6e43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
      SearchScopes: HKU\S-1-5-21-1917681920-812532136-750919602-1001 -> DefaultScope {25AEA4C0-6ABA-42AD-8BCD-644EB82536FD} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWJoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=NGVaMGV9NaJ4MZ%3D%3D&p={searchTerms}
      SearchScopes: HKU\S-1-5-21-1917681920-812532136-750919602-1001 -> {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
      SearchScopes: HKU\S-1-5-21-1917681920-812532136-750919602-1001 -> {25AEA4C0-6ABA-42AD-8BCD-644EB82536FD} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=arh&hsimp=yhs-001&type=xy_76ab17bc&param1=ArFaIWJoNqArQGMVHFFoNqAqBbFaITQbQGR7xTVoN9IAy7IsQGR7B7JoN9JbDSk8vFE9GqQANFdcFCk8vFI4JaYTvFJdJGYYvFM4JmoVwVQ9JqYYNVFdJqYVvmo9GqYVNUI3wGYGwVM4J6k4wVU9GqUNNos3wCIYwVA9JmIYwVA9J6ITwVI9GqUNNFM3wGQENEVcGCIXvFI9ImIWwVA9J6ILNFdcIaUXNEBcGqQANFdcFCk8NoM4IWYWvFI9ISoWvFM4JqYXwVw4J6oXvFQ9JmISvFI4JqYUvFE9I6oUwVM4ICk3wVw4ISk4wVQ9JmoXvFI4JmoXNVM3vGYYNVFbFCILNF9cIqUXNolcEqULNopcGWUIvmFbFaYVvFI9JqYXwVU9IWYYwVI9IaYTvFQ4IWYWwVw4ICk3vFQ9JCISNVU4ISoXwVM9I6oWwVRdICIYvmo4ISoUwVI9ISk3NVA3vGQIwV5dJGYNvmE4IHFbMnMbQGMVNGBcMWF7MqJ7NXFbMnVoN9I4ATsux81cMo1aN80exnwfyU0rASRbNr5bOqVoNqAex807ACRoN9JcNX5dQGR7y6NoN9ICzD4py6waQGQXNGZoNpQRy78oQGQXF7ofA7coQGQXGTUfA6EsA7F%3D&param2=NGVaMGV9NaJ4MZ%3D%3D&p={searchTerms}
      SearchScopes: HKU\S-1-5-21-1917681920-812532136-750919602-1001 -> {a62abdee-78a2-4ddb-9355-1c334abd6e43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
      BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-31] (Microsoft Corporation)
      BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
      BHO: Sem Nome -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> Nenhum Arquivo
      BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-31] (Microsoft Corporation)
      BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-31] (Microsoft Corporation)
      BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
      BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-31] (Microsoft Corporation)
      Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
      Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
      Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-31] (Microsoft Corporation)
      Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-31] (Microsoft Corporation)
      Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-31] (Microsoft Corporation)
      Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-31] (Microsoft Corporation)
      StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox:
      ========
      FF ProfilePath: C:\Users\eliete-ma1hotmail.co\AppData\Roaming\Mozilla\Firefox\Profiles\gyh8f1bc.default
      FF NewTab: about:newtab
      FF Homepage: hxxp://www.bing.com/search?FORM=INCOH1&PC=IC04&PTAG=ICO-44a76390
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
      FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-31] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-07-31] (Microsoft Corporation)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
      FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon
      FF Extension: (Norton Identity Safe) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon [2016-08-20]
      FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon
      StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: 
      =======
      CHR Profile: C:\Users\eliete-ma1hotmail.co\AppData\Local\Google\Chrome\User Data\Default
      CHR Extension: (Norton Security Toolbar) - C:\Users\eliete-ma1hotmail.co\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2016-08-24]
      CHR Extension: (Norton Identity Safe) - C:\Users\eliete-ma1hotmail.co\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2016-08-24]
      CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\eliete-ma1hotmail.co\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-24]
      CHR Extension: (Chrome Media Router) - C:\Users\eliete-ma1hotmail.co\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-24]
      CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\Exts\Chrome.crx [2016-08-21]
      CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
      CHR HKU\S-1-5-21-1917681920-812532136-750919602-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\Exts\Chrome.crx [2016-08-21]
      CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [172104 2013-01-26] (Adobe Systems Incorporated)
      R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-20] (Samsung) [Arquivo não assinado]
      R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2854640 2016-07-31] (Microsoft Corporation)
      R2 ETDService; C:\Program Files\Elantech\ETDService.exe [139984 2015-09-23] (ELAN Microelectronics Corp.)
      R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [329280 2016-02-19] (Intel Corporation)
      R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [Arquivo não assinado]
      S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
      R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
      R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
      R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\NIS.exe [289080 2016-08-16] (Symantec Corporation)
      R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-02-13] (Copyright 2013 SAMSUNG)
      R2 Settings Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe [1594176 2014-04-21] (Samsung Electronics CO., LTD.)
      R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3287848 2016-02-24] (Samsung Electronics Co., Ltd.)
      S3 vmicvss; C:\Windows\System32\ICSvc.dll [511488 2015-10-30] (Microsoft Corporation)
      S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
      R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation)
      R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-01-06] (Atheros) [Arquivo não assinado] ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\BASHDefs\20160125.001\BHDrvx64.sys [1665608 2015-10-21] (Symantec Corporation)
      R1 cbfs3; C:\windows\system32\drivers\cbfs3.sys [352448 2013-02-11] (EldoS Corporation)
      R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1607010.020\ccSetx64.sys [174328 2016-06-02] (Symantec Corporation)
      S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
      R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497392 2016-04-27] (Symantec Corporation)
      U3 EraserUtilDrv11521; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11521.sys [156912 2016-04-27] (Symantec Corporation)
      S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [157520 2015-11-18] (Symantec Corporation)
      R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [41024 2015-09-23] (ELAN Microelectronic Corp.)
      S3 FlashUSB; C:\Windows\System32\drivers\FlashUSB.sys [19968 2013-06-05] (Intel Mobile Communications)
      R3 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\IPSDefs\20160201.001\IDSvia64.sys [767224 2015-12-04] (Symantec Corporation)
      R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
      R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation)
      R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
      R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
      S3 shspusb; C:\Windows\System32\drivers\HSPUSB.sys [24064 2013-06-05] (MobileTop)
      R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1607010.020\SRTSP64.SYS [773360 2016-08-09] (Symantec Corporation)
      R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1607010.020\SRTSPX64.SYS [48888 2016-06-02] (Symantec Corporation)
      S3 sscdserd; C:\Windows\System32\drivers\sscdserd.sys [158024 2013-06-05] (MCCI Corporation)
      S3 ssceserd; C:\Windows\System32\drivers\ssceserd.sys [158024 2013-06-05] (MCCI Corporation)
      S3 ssdudfu; C:\Windows\System32\drivers\ssdudfu.sys [101960 2013-06-05] (MCCI)
      S3 ssm_bus; C:\Windows\System32\drivers\ssm_bus.sys [136192 2013-06-05] (MCCI Corporation)
      S3 ssm_mdm; C:\Windows\System32\drivers\ssm_mdm.sys [172032 2013-06-05] (MCCI Corporation)
      S3 ssuddmgr; C:\Windows\System32\drivers\ssuddmgr.sys [203672 2013-06-05] (DEVGURU Co., LTD.(www.devguru.co.kr))
      S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
      S3 ssudobex; C:\Windows\System32\drivers\ssudobex.sys [203672 2013-06-05] (DEVGURU Co., LTD.(www.devguru.co.kr))
      S3 ssudrmnet; C:\Windows\System32\drivers\ssudrmnet.sys [67864 2013-06-05] (DEVGURU Co., LTD.)
      S3 ssudserd; C:\Windows\System32\drivers\ssudserd.sys [203672 2013-06-05] (DEVGURU Co., LTD.(www.devguru.co.kr))
      S3 ss_bserd; C:\Windows\System32\drivers\ss_bserd.sys [128000 2013-06-05] (MCCI Corporation)
      R0 SymEFASI; C:\Windows\System32\drivers\NISx64\1607010.020\SYMEFASI64.SYS [1627352 2016-06-02] (Symantec Corporation)
      S4 SymELAM; C:\Windows\system32\drivers\NISx64\1607010.020\SymELAM.sys [24192 2015-09-23] (Symantec Corporation)
      R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [101112 2016-08-10] (Symantec Corporation)
      R3 SymIRON; C:\Windows\system32\drivers\NISx64\1607010.020\Ironx64.SYS [291056 2016-06-02] (Symantec Corporation)
      R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1607010.020\SYMNETS.SYS [567536 2016-06-02] (Symantec Corporation)
      S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [23040 2015-10-30] (Microsoft Corporation)
      S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
      R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
      S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
      S1 lfnhyvcc; \??\C:\WINDOWS\system32\drivers\lfnhyvcc.sys [X]
      S3 NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\VirusDefs\20160202.003\ENG64.SYS [X]
      S3 NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\VirusDefs\20160202.003\EX64.SYS [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
      ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-08-28 00:21 - 2016-08-28 00:22 - 00030369 _____ C:\Users\eliete-ma1hotmail.co\Desktop\FRST.txt
      2016-08-28 00:04 - 2016-08-28 00:21 - 00000000 ____D C:\FRST
      2016-08-28 00:01 - 2016-08-28 00:02 - 02396672 _____ (Farbar) C:\Users\eliete-ma1hotmail.co\Desktop\FRST64.exe
      2016-08-24 16:34 - 2016-08-24 16:34 - 00087459 _____ C:\Users\eliete-ma1hotmail.co\Desktop\mbam-setup-2.2.1.1043.txt
      2016-08-24 15:28 - 2016-08-24 16:22 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
      2016-08-24 15:27 - 2016-08-24 15:27 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
      2016-08-24 15:27 - 2016-08-24 15:27 - 00000000 ____D C:\Users\Todos os Usuários\Malwarebytes
      2016-08-24 15:27 - 2016-08-24 15:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
      2016-08-24 15:27 - 2016-08-24 15:27 - 00000000 ____D C:\ProgramData\Malwarebytes
      2016-08-24 15:27 - 2016-08-24 15:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
      2016-08-24 15:27 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
      2016-08-24 15:27 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
      2016-08-24 15:27 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
      2016-08-24 15:21 - 2016-08-24 15:23 - 00008011 _____ C:\Users\eliete-ma1hotmail.co\Desktop\ZHPCleaner.txt
      2016-08-24 15:06 - 2016-08-24 15:23 - 00000000 ____D C:\Users\eliete-ma1hotmail.co\AppData\Roaming\ZHP
      2016-08-24 15:06 - 2016-08-24 15:06 - 00000890 _____ C:\Users\eliete-ma1hotmail.co\Desktop\ZHPCleaner.lnk
      2016-08-24 14:58 - 2016-08-24 14:58 - 00001288 _____ C:\Users\eliete-ma1hotmail.co\Desktop\JRT.txt
      2016-08-24 14:42 - 2016-08-24 14:42 - 00005822 _____ C:\Users\eliete-ma1hotmail.co\Desktop\AdwCleaner[S0].txt
      2016-08-24 14:37 - 2016-08-24 14:40 - 00000000 ____D C:\AdwCleaner
      2016-08-24 14:37 - 2016-08-24 14:37 - 00001954 _____ C:\Users\eliete-ma1hotmail.co\Desktop\sc-cleaner.txt
      2016-08-24 14:34 - 2016-08-24 14:36 - 22851472 _____ (Malwarebytes ) C:\Users\eliete-ma1hotmail.co\Desktop\mbam-setup-2.2.1.1043.exe
      2016-08-24 14:33 - 2016-08-24 14:33 - 02349056 _____ C:\Users\eliete-ma1hotmail.co\Desktop\ZHPCleaner.exe
      2016-08-24 14:31 - 2016-08-24 14:32 - 01610560 _____ (Malwarebytes) C:\Users\eliete-ma1hotmail.co\Desktop\JRT.exe
      2016-08-24 14:30 - 2016-08-24 14:31 - 03784256 _____ C:\Users\eliete-ma1hotmail.co\Desktop\adwcleaner_6.000.exe
      2016-08-24 14:27 - 2016-08-24 14:28 - 00465024 _____ (Bleeping Computer, LLC) C:\Users\eliete-ma1hotmail.co\Desktop\sc-cleaner.exe
      2016-08-23 17:08 - 2016-08-24 16:22 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security
      2016-08-23 17:02 - 2016-08-23 17:02 - 00003404 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration
      2016-08-23 16:58 - 2016-08-23 17:01 - 00286020 _____ C:\WINDOWS\Minidump\082316-50734-01.dmp
      2016-08-20 17:28 - 2016-08-20 17:33 - 00000512 _____ C:\Users\eliete-ma1hotmail.co\Desktop\Dump_Hdd0_DR0.mbr
      2016-08-20 17:26 - 2016-08-20 17:26 - 00027300 _____ C:\ZA-Scan.txt
      2016-08-20 15:54 - 2016-08-20 15:54 - 00000000 ____D C:\zoek_backup
      2016-08-20 11:12 - 2016-08-20 11:13 - 01370112 _____ C:\Users\eliete-ma1hotmail.co\Desktop\ZA-Scan.exe
      2016-08-19 00:48 - 2016-08-19 00:48 - 140992312 _____ C:\Users\eliete-ma1hotmail.co\Downloads\TODOS OS CARGOS.zip
      2016-08-19 00:09 - 2016-08-19 00:09 - 138197574 _____ C:\Users\eliete-ma1hotmail.co\Downloads\Analista.zip
      2016-08-14 20:04 - 2016-08-14 20:04 - 00452524 _____ C:\Users\eliete-ma1hotmail.co\Downloads\Sociedade Civil e Gramcs.pdf
      2016-08-11 14:22 - 2016-08-11 14:22 - 00204754 _____ C:\Users\eliete-ma1hotmail.co\Downloads\2_3_Fundamentos_eticos_do_Servico_Social.pdf
      2016-08-10 14:38 - 2016-08-03 07:23 - 00693600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
      2016-08-10 14:38 - 2016-08-03 07:22 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
      2016-08-10 14:38 - 2016-08-03 07:21 - 00566112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
      2016-08-10 14:38 - 2016-08-03 07:19 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
      2016-08-10 14:38 - 2016-08-03 07:19 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
      2016-08-10 14:38 - 2016-08-03 07:13 - 01988448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
      2016-08-10 14:38 - 2016-08-03 07:13 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
      2016-08-10 14:38 - 2016-08-03 07:13 - 00393056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
      2016-08-10 14:38 - 2016-08-03 06:51 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
      2016-08-10 14:38 - 2016-08-03 06:44 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
      2016-08-10 14:38 - 2016-08-03 06:44 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
      2016-08-10 14:38 - 2016-08-03 06:43 - 16985088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
      2016-08-10 14:38 - 2016-08-03 06:41 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys
      2016-08-10 14:38 - 2016-08-03 06:41 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
      2016-08-10 14:38 - 2016-08-03 06:40 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
      2016-08-10 14:38 - 2016-08-03 06:40 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
      2016-08-10 14:38 - 2016-08-03 06:40 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
      2016-08-10 14:38 - 2016-08-03 06:38 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
      2016-08-10 14:38 - 2016-08-03 06:36 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
      2016-08-10 14:38 - 2016-08-03 06:31 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
      2016-08-10 14:38 - 2016-08-03 06:30 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
      2016-08-10 14:38 - 2016-08-03 06:29 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
      2016-08-10 14:38 - 2016-08-03 06:29 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
      2016-08-10 14:38 - 2016-08-03 06:29 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
      2016-08-10 14:38 - 2016-08-03 06:29 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
      2016-08-10 14:38 - 2016-08-03 06:18 - 06974464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
      2016-08-10 14:38 - 2016-08-03 06:18 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
      2016-08-10 14:38 - 2016-08-03 06:16 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
      2016-08-10 14:38 - 2016-08-03 06:16 - 03589120 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
      2016-08-10 14:38 - 2016-08-03 06:14 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
      2016-08-10 14:38 - 2016-08-03 06:11 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
      2016-08-10 14:38 - 2016-08-03 02:52 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
      2016-08-10 14:38 - 2016-08-03 02:34 - 00501592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
      2016-08-10 14:38 - 2016-08-03 02:34 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
      2016-08-10 14:38 - 2016-08-03 02:33 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
      2016-08-10 14:38 - 2016-08-03 02:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
      2016-08-10 14:38 - 2016-08-03 01:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
      2016-08-10 14:38 - 2016-08-03 01:44 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
      2016-08-10 14:38 - 2016-08-03 01:32 - 12585984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
      2016-08-10 14:38 - 2016-08-03 01:25 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
      2016-08-10 14:38 - 2016-08-03 01:19 - 02180096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
      2016-08-10 14:37 - 2016-08-03 08:14 - 01505984 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
      2016-08-10 14:37 - 2016-08-03 08:14 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
      2016-08-10 14:37 - 2016-08-03 08:14 - 00050368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
      2016-08-10 14:37 - 2016-08-03 07:36 - 07469408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
      2016-08-10 14:37 - 2016-08-03 07:36 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
      2016-08-10 14:37 - 2016-08-03 07:36 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
      2016-08-10 14:37 - 2016-08-03 07:30 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
      2016-08-10 14:37 - 2016-08-03 07:23 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
      2016-08-10 14:37 - 2016-08-03 07:22 - 01322760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
      2016-08-10 14:37 - 2016-08-03 07:22 - 00465248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
      2016-08-10 14:37 - 2016-08-03 07:22 - 00331616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
      2016-08-10 14:37 - 2016-08-03 07:21 - 03675512 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
      2016-08-10 14:37 - 2016-08-03 07:21 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
      2016-08-10 14:37 - 2016-08-03 07:20 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
      2016-08-10 14:37 - 2016-08-03 07:20 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
      2016-08-10 14:37 - 2016-08-03 06:51 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdlrecover.exe
      2016-08-10 14:37 - 2016-08-03 06:46 - 22384128 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
      2016-08-10 14:37 - 2016-08-03 06:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
      2016-08-10 14:37 - 2016-08-03 06:41 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
      2016-08-10 14:37 - 2016-08-03 06:41 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
      2016-08-10 14:37 - 2016-08-03 06:40 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
      2016-08-10 14:37 - 2016-08-03 06:39 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
      2016-08-10 14:37 - 2016-08-03 06:39 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
      2016-08-10 14:37 - 2016-08-03 06:38 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
      2016-08-10 14:37 - 2016-08-03 06:37 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
      2016-08-10 14:37 - 2016-08-03 06:36 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
      2016-08-10 14:37 - 2016-08-03 06:35 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
      2016-08-10 14:37 - 2016-08-03 06:35 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
      2016-08-10 14:37 - 2016-08-03 06:33 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
      2016-08-10 14:37 - 2016-08-03 06:31 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
      2016-08-10 14:37 - 2016-08-03 06:30 - 24613888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
      2016-08-10 14:37 - 2016-08-03 06:29 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
      2016-08-10 14:37 - 2016-08-03 06:29 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
      2016-08-10 14:37 - 2016-08-03 06:29 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
      2016-08-10 14:37 - 2016-08-03 06:28 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
      2016-08-10 14:37 - 2016-08-03 06:28 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
      2016-08-10 14:37 - 2016-08-03 06:28 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
      2016-08-10 14:37 - 2016-08-03 06:27 - 07536640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
      2016-08-10 14:37 - 2016-08-03 06:27 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
      2016-08-10 14:37 - 2016-08-03 06:27 - 01717760 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
      2016-08-10 14:37 - 2016-08-03 06:27 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
      2016-08-10 14:37 - 2016-08-03 06:20 - 13390336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
      2016-08-10 14:37 - 2016-08-03 06:18 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
      2016-08-10 14:37 - 2016-08-03 06:17 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
      2016-08-10 14:37 - 2016-08-03 06:16 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
      2016-08-10 14:37 - 2016-08-03 06:16 - 01732096 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
      2016-08-10 14:37 - 2016-08-03 06:15 - 07833088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
      2016-08-10 14:37 - 2016-08-03 06:14 - 04895232 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
      2016-08-10 14:37 - 2016-08-03 06:13 - 03025920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
      2016-08-10 14:37 - 2016-08-03 06:13 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
      2016-08-10 14:37 - 2016-08-03 06:12 - 02746368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
      2016-08-10 14:37 - 2016-08-03 02:31 - 02921368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
      2016-08-10 14:37 - 2016-08-03 02:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
      2016-08-10 14:37 - 2016-08-03 02:30 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
      2016-08-10 14:37 - 2016-08-03 02:30 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
      2016-08-10 14:37 - 2016-08-03 02:30 - 00255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
      2016-08-10 14:37 - 2016-08-03 01:57 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdlrecover.exe
      2016-08-10 14:37 - 2016-08-03 01:48 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
      2016-08-10 14:37 - 2016-08-03 01:47 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
      2016-08-10 14:37 - 2016-08-03 01:42 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
      2016-08-10 14:37 - 2016-08-03 01:40 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
      2016-08-10 14:37 - 2016-08-03 01:39 - 19351040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
      2016-08-10 14:37 - 2016-08-03 01:37 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
      2016-08-10 14:37 - 2016-08-03 01:35 - 00178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
      2016-08-10 14:37 - 2016-08-03 01:34 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
      2016-08-10 14:37 - 2016-08-03 01:34 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
      2016-08-10 14:37 - 2016-08-03 01:33 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
      2016-08-10 14:37 - 2016-08-03 01:33 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
      2016-08-10 14:37 - 2016-08-03 01:33 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
      2016-08-10 14:37 - 2016-08-03 01:32 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
      2016-08-10 14:37 - 2016-08-03 01:32 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
      2016-08-10 14:37 - 2016-08-03 01:32 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
      2016-08-10 14:37 - 2016-08-03 01:31 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
      2016-08-10 14:37 - 2016-08-03 01:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
      2016-08-10 14:37 - 2016-08-03 01:29 - 12133376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
      2016-08-10 14:37 - 2016-08-03 01:28 - 03663360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
      2016-08-10 14:37 - 2016-08-03 01:25 - 05323776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
      2016-08-10 14:37 - 2016-08-03 01:23 - 05660672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
      2016-08-10 14:37 - 2016-08-03 01:23 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
      2016-08-10 14:37 - 2016-08-03 01:22 - 02501120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
      2016-08-10 14:37 - 2016-08-03 01:22 - 01502208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
      2016-08-10 14:37 - 2016-08-03 01:21 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
      2016-08-10 14:36 - 2016-08-03 07:22 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
      2016-08-10 14:36 - 2016-08-03 07:21 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
      2016-08-10 14:36 - 2016-08-03 07:11 - 00422744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
      2016-08-10 14:36 - 2016-08-03 06:40 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
      2016-08-10 14:36 - 2016-08-03 06:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
      2016-08-10 14:36 - 2016-08-03 06:34 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
      2016-08-10 14:36 - 2016-08-03 06:33 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
      2016-08-10 14:36 - 2016-08-03 06:31 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
      2016-08-10 14:36 - 2016-08-03 06:30 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
      2016-08-10 14:36 - 2016-08-03 01:37 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
      2016-08-10 14:36 - 2016-08-03 01:35 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
      2016-07-29 10:32 - 2016-07-29 10:33 - 00000000 ___HD C:\Users\eliete-ma1hotmail.co\AppData\Local\07554d7f089c417d ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-08-27 22:40 - 2016-07-17 17:40 - 00000330 _____ C:\WINDOWS\Tasks\{5351C598-7E87-2E7A-E949-7CB6E6D65AA2}.job
      2016-08-27 22:31 - 2016-04-14 19:32 - 00004192 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BFCB3FE1-0C03-48E7-BE29-2A2BA6428CF3}
      2016-08-27 22:24 - 2015-11-04 20:50 - 00001090 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
      2016-08-27 19:34 - 2016-03-23 11:23 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
      2016-08-27 09:37 - 2015-10-30 04:24 - 00000000 ___HD C:\Program Files\WindowsApps
      2016-08-27 09:37 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\AppReadiness
      2016-08-25 19:21 - 2016-03-08 13:21 - 01819274 _____ C:\WINDOWS\system32\PerfStringBackup.INI
      2016-08-25 19:21 - 2015-10-30 16:12 - 00785460 _____ C:\WINDOWS\system32\prfh0416.dat
      2016-08-25 19:21 - 2015-10-30 16:12 - 00154246 _____ C:\WINDOWS\system32\prfc0416.dat
      2016-08-25 19:21 - 2015-10-30 04:21 - 00000000 ____D C:\WINDOWS\INF
      2016-08-24 16:21 - 2014-06-23 00:39 - 00000000 ____D C:\Users\Todos os Usuários\WinClon
      2016-08-24 16:21 - 2014-06-23 00:39 - 00000000 ____D C:\ProgramData\WinClon
      2016-08-24 16:18 - 2015-10-30 04:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
      2016-08-24 16:16 - 2016-03-08 13:33 - 00000000 __SHD C:\Users\eliete-ma1hotmail.co\IntelGraphicsProfiles
      2016-08-24 16:15 - 2016-03-08 13:06 - 00000000 ____D C:\Users\eliete-ma1hotmail.co
      2016-08-24 16:14 - 2016-03-08 13:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
      2016-08-24 16:14 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\System
      2016-08-24 16:13 - 2015-10-30 03:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
      2016-08-24 14:54 - 2015-12-04 09:57 - 00000000 ____D C:\Users\eliete-ma1hotmail.co\AppData\Local\CrashDumps
      2016-08-24 13:00 - 2016-03-30 09:20 - 00001967 _____ C:\Users\Public\Desktop\Samsung Update.lnk
      2016-08-23 17:03 - 2015-10-30 03:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
      2016-08-23 17:02 - 2015-11-17 09:14 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
      2016-08-23 17:02 - 2015-11-16 09:55 - 00002496 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk
      2016-08-23 17:02 - 2014-06-23 00:37 - 00000000 ____D C:\WINDOWS\system32\Drivers\NISx64
      2016-08-23 16:58 - 2016-03-23 11:17 - 00000000 ____D C:\WINDOWS\Minidump
      2016-08-23 16:58 - 2015-12-02 09:50 - 644902081 _____ C:\WINDOWS\MEMORY.DMP
      2016-08-22 08:40 - 2016-03-02 14:32 - 00000271 _____ C:\Users\eliete-ma1hotmail.co\AppData\Roaming\WB.CFG
      2016-08-21 12:30 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\rescache
      2016-08-20 18:38 - 2015-07-28 22:16 - 00000000 ____D C:\Users\eliete-ma1hotmail.co\Desktop\TRE
      2016-08-20 16:20 - 2015-06-13 23:24 - 00000000 __RHD C:\Users\Public\AccountPictures
      2016-08-20 16:07 - 2015-10-30 16:15 - 00000000 ____D C:\Program Files\Windows Journal
      2016-08-20 16:07 - 2015-10-30 04:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
      2016-08-20 16:07 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
      2016-08-20 12:36 - 2015-10-30 04:24 - 00000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft
      2016-08-20 12:36 - 2015-10-30 04:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
      2016-08-20 12:31 - 2016-03-05 18:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
      2016-08-20 11:49 - 2016-04-12 14:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
      2016-08-20 11:42 - 2016-03-02 13:31 - 00000286 __RSH C:\Users\Todos os Usuários\ntuser.pol
      2016-08-20 11:42 - 2016-03-02 13:31 - 00000286 __RSH C:\ProgramData\ntuser.pol
      2016-08-20 11:38 - 2015-10-30 04:11 - 00000000 ____D C:\WINDOWS\CbsTemp
      2016-08-19 00:41 - 2016-03-08 13:39 - 00002414 _____ C:\Users\eliete-ma1hotmail.co\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
      2016-08-19 00:41 - 2015-09-06 16:38 - 00000000 ___RD C:\Users\eliete-ma1hotmail.co\OneDrive
      2016-08-12 15:28 - 2016-05-11 12:32 - 00000000 ____D C:\Users\eliete-ma1hotmail.co\AppData\Local\{E0D7D68B-C47F-BA33-A9E7-9FDB8D8F6343}
      2016-08-11 14:27 - 2015-11-07 21:08 - 00000000 ____D C:\WINDOWS\system32\MRT
      2016-08-11 14:27 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
      2016-08-11 14:18 - 2015-11-07 21:08 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
      2016-08-10 12:12 - 2014-06-23 00:39 - 00101112 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
      2016-08-10 12:12 - 2014-06-23 00:39 - 00008270 _____ C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
      2016-08-08 17:28 - 2015-11-04 20:54 - 00002270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
      2016-08-08 17:28 - 2015-11-04 20:54 - 00002258 _____ C:\Users\Public\Desktop\Google Chrome.lnk ==================== Arquivos na raiz de alguns diretórios ======= 2016-07-02 17:33 - 2016-07-02 17:33 - 3167251 _____ () C:\Users\eliete-ma1hotmail.co\AppData\Roaming\sb78.dat
      2016-03-02 14:32 - 2016-08-22 08:40 - 0000271 _____ () C:\Users\eliete-ma1hotmail.co\AppData\Roaming\WB.CFG
      2016-03-08 13:02 - 2016-03-08 13:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
      2014-06-23 01:00 - 2013-02-19 04:34 - 2064264 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
      2014-06-23 01:00 - 2013-01-12 11:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml Arquivos para serem movidos ou deletados:
      ====================
      C:\Windows\Tasks\{5351C598-7E87-2E7A-E949-7CB6E6D65AA2}.job
      ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente
      LastRegBack: 2016-08-22 17:31 ==================== Fim de FRST.txt ============================         Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 27-08-2016
      Executado por eliete-ma1hotmail.co (28-08-2016 00:23:43)
      Executando a partir de C:\Users\eliete-ma1hotmail.co\Desktop
      Windows 10 Home Single Language Versão 1511 (X64) (2016-03-08 16:31:52)
      Modo da Inicialização: Normal
      ==========================================================
      ==================== Contas: ============================= Administrador (S-1-5-21-1917681920-812532136-750919602-500 - Administrator - Disabled) => C:\Users\Administrator
      Convidado (S-1-5-21-1917681920-812532136-750919602-501 - Limited - Disabled)
      DefaultAccount (S-1-5-21-1917681920-812532136-750919602-503 - Limited - Disabled)
      eliete-ma1hotmail.co (S-1-5-21-1917681920-812532136-750919602-1001 - Administrator - Enabled) => C:\Users\eliete-ma1hotmail.co
      HomeGroupUser$ (S-1-5-21-1917681920-812532136-750919602-1003 - Limited - Enabled) ==================== Central de Segurança ======================== (Se uma entrada for incluída na fixlist, será removida.) AV: Norton Internet Security (Disabled - Out of date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
      AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: Norton Internet Security (Disabled - Out of date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
      FW: Norton Internet Security (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Programas Instalados ====================== (Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.) Adobe Photoshop Elements 11 (HKLM-x32\...\Adobe Photoshop Elements 11) (Version: 11.0 - Adobe Systems Incorporated)
      AllShare Framework DMS (HKLM\...\{83232C27-8C3F-44A5-9EB2-BB7161228ADD}) (Version: 1.3.23 - Samsung)
      Bitcasa version 1.0.1.5011 (HKLM\...\{EDA09459-AD7D-4434-BA0C-647F6703EA12}_is1) (Version: 1.0.1.5011 - Bitcasa Inc.)
      Elements 11 Organizer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
      ETDWare X64 15.7.0.1_WHQL (HKLM\...\Elantech) (Version: 15.7.0.1 - ELAN Microelectronic Corp.)
      Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
      Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
      Help Desk (HKLM\...\{AEC9D273-E162-4614-83F1-722B8C74B185}) (Version: 1.0.96 - Samsung Electronics CO., LTD.)
      Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
      Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
      Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.3.1000 - Intel Corporation)
      Malwarebytes Anti-Malware versão 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
      Microsoft Office 365 ProPlus - pt-br (HKLM\...\O365ProPlusRetail - pt-br) (Version: 16.0.6741.2063 - Microsoft Corporation)
      Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Mozilla Firefox 47.0.1 (x86 pt-BR) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 pt-BR)) (Version: 47.0.1 - Mozilla)
      Norton Internet Security (HKLM-x32\...\NIS) (Version: 22.7.1.32 - Symantec Corporation)
      Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6701.1036 - Microsoft Corporation) Hidden
      Office 16 Click-to-Run Licensing Component (Version: 16.0.6701.1036 - Microsoft Corporation) Hidden
      Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6701.1036 - Microsoft Corporation) Hidden
      Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 2.0.0.21 - RSUPPORT)
      PSE11 STI Installer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
      Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
      Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
      Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
      Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.)
      Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.1.0.3 - Samsung Electronics CO., LTD.)
      Revisores de Texto do Microsoft Office 2013 – Português do Brasil (x32 Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
      Revo Uninstaller Pro 3.1.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.5 - VS Revo Group, Ltd.)
      S Agent (Version: 1.1.58 - Samsung Electronics Co., Ltd.) Hidden
      Samsung Link (HKLM-x32\...\{82EC241F-DFCA-4166-A8C3-EA5D2B9A41C4}) (Version: 1.8.0.31 - Samsung Electronics CO., LTD.)
      Samsung Link 1.8.0.1402131807 (HKLM\...\8474-7877-9059-0204) (Version: 1.8.0.1402131807 - Copyright 2013 SAMSUNG)
      Samsung Update (HKLM-x32\...\{00935958-A0DE-45AF-A3EA-F6960A99785C}) (Version: 2.2.32 - Samsung Electronics Co., Ltd.)
      SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.25.0 - SAMSUNG Electronics Co., Ltd.)
      Search the Web (Yahoo) (HKLM-x32\...\a92e2408) (Version:  - )
      Settings (HKLM-x32\...\{3BB58176-B3A7-47FD-9F18-C3576431D193}) (Version: 2.2.0 - Samsung Electronics CO., LTD.)
      SideSync (HKLM-x32\...\{59687468-8CE9-4ABF-9C6A-5C31F0E09F8B}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
      User Manual (HKLM-x32\...\{DA11CC4A-5E90-4EA9-8E7B-29D5328E35F0}) (Version: 2.0.00 - Samsung Electronics CO., LTD.)
      Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass  (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.)
      WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Exame Personalizado CLSID (Whitelisted): ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) CustomCLSID: HKU\S-1-5-21-1917681920-812532136-750919602-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-1917681920-812532136-750919602-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Tarefas Agendadas (Whitelisted) ============= (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {08254F35-95A5-4572-B988-440C50DE41EE} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\SymErr.exe [2016-05-23] (Symantec Corporation)
      Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
      Task: {0E4B8DA1-F753-44AA-9906-DC7B67300726} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Nenhum Arquivo <==== ATENÇÃO
      Task: {121E4307-9DC5-4A68-9609-55C8AAAD307D} - System32\Tasks\Norton Internet Security\Norton Autofix => C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\SymErr.exe [2016-05-23] (Symantec Corporation)
      Task: {199C167E-D6E1-4DF8-85F8-EA30558AC8FB} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
      Task: {1DB3C230-C87B-4437-921F-D7F38FF514F4} - System32\Tasks\SamsungLinkPC => C:\Program Files (x86)\Samsung\HomeSync Lite\RefreshToken.exe
      Task: {1FA1E71D-713E-47E0-BE93-33F75F64156B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Nenhum Arquivo <==== ATENÇÃO
      Task: {275A3999-72DC-43B9-A877-902FD278FC7C} - System32\Tasks\{5351C598-7E87-2E7A-E949-7CB6E6D65AA2} => C:\Users\ELIETE~1.CO\AppData\Roaming\{CBEDF~1\synctask.exe <==== ATENÇÃO
      Task: {2F13F97D-503A-4AF4-8D3D-86855D049CDB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Nenhum Arquivo <==== ATENÇÃO
      Task: {30793764-2C39-41FE-B48E-9C022A7F29C4} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Nenhum Arquivo <==== ATENÇÃO
      Task: {46B0FD51-7735-4F33-81AC-9030E3FD7133} - System32\Tasks\DisplayChecker => C:\programdata\Samsung\_DisplayChecker.exe [2013-12-10] (TODO: <Company name>)
      Task: {496665D2-E002-4609-B56D-1E1CA033908E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-04] (Google Inc.)
      Task: {49BEA4A3-A85F-47FC-ABE4-715F73EC9EDD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Nenhum Arquivo <==== ATENÇÃO
      Task: {4E838A64-2E0B-4576-AB47-631FAA48A4E2} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Nenhum Arquivo <==== ATENÇÃO
      Task: {54C50B28-7EEA-451C-8918-52F2DFDFED73} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-31] (Microsoft Corporation)
      Task: {596B0E76-5263-499F-B48E-7DC025C9632A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
      Task: {60703A46-B8BF-4EEC-8967-35A2035959E1} - \AutoPico Daily Restart -> Nenhum Arquivo <==== ATENÇÃO
      Task: {6723B51C-05CE-48B2-BD9A-4AD1F0A8AEC7} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\WSCStub.exe [2016-08-16] (Symantec Corporation)
      Task: {68E82C38-243C-4B50-B55F-10C429486728} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-08-28] (Realtek Semiconductor)
      Task: {68F02E32-BD6D-4643-95F0-34C16EAB8F48} - System32\Tasks\ShutdownOpt => C:\ProgramData\Samsung\ShutdownEvent.exe [2013-09-17] (SAMSUNG Electronics co., LTD.)
      Task: {6B6E44F3-59AA-4A74-A50E-A916A64CA207} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Nenhum Arquivo <==== ATENÇÃO
      Task: {6DF66265-015C-429C-8278-EAE48F8DA422} - \eliete-ma1hotmail.coMetronomeRecenciesV2 -> Nenhum Arquivo <==== ATENÇÃO
      Task: {7AF7518E-770C-4A45-8DE5-FD4AA9029F03} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-31] (Microsoft Corporation)
      Task: {7E21B405-6089-42A5-B223-7B4669490D0F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-08-01] (Microsoft Corporation)
      Task: {7E65150A-2F93-41D9-B23E-38FA5501CD6D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\22.7.1.32\SymErr.exe [2016-05-23] (Symantec Corporation)
      Task: {8252C30C-7A27-4C38-8A55-D8A621B78F79} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Nenhum Arquivo <==== ATENÇÃO
      Task: {8A02EC4F-2863-4DF5-BD08-A8DCF9017FE3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-08-01] (Microsoft Corporation)
      Task: {8CC84D46-D291-459E-86FE-7B95EE38C228} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Nenhum Arquivo <==== ATENÇÃO
      Task: {8D0696B6-9ED5-460E-AA76-7B0D70FFDF7F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Nenhum Arquivo <==== ATENÇÃO
      Task: {A3FEAAA8-86C0-4591-89EB-87E6498F4368} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Nenhum Arquivo <==== ATENÇÃO
      Task: {B3D47F0D-8207-4A9E-9D6B-0983678925FC} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Nenhum Arquivo <==== ATENÇÃO
      Task: {C357F124-654B-4FBA-B8B7-E6B6A3301462} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-04] (Google Inc.)
      Task: {C4705D1B-FF84-47F0-BAA8-36D34FD507CB} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2016-08-16] (Symantec Corporation)
      Task: {D42F56E4-FB45-456B-9BD6-C358C038E1D1} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2016-07-05] (SEC)
      Task: {E417EB21-B478-4D11-A5B4-5D3A28487B7B} - System32\Tasks\LaunchSettings => C:\Program Files (x86)\Samsung\Settings\Settings.exe [2014-04-21] ()
      Task: {EDCB4F06-6C66-47C3-B386-F7A1B5BB1D64} - System32\Tasks\SUPatchForW10Up => C:\ProgramData\Samsung\SamsungUpdatePatch\SUPatchForW10Up.exe [2015-08-18] (Samsung Electronics CO., LTD.)
      Task: {EF08709D-9A91-449A-A36B-CA78160F89B9} - System32\Tasks\SettingsEventHandlerMonitor => C:\Program Files (x86)\Samsung\Settings\CmdServer\RSSettingEventHandler.exe [2014-04-21] (Samsung Electronics CO., LTD.)
      Task: {F25E08DC-72A6-4021-A1C7-F41053FDC253} - System32\Tasks\SettingsHibernateMonitor => C:\Program Files (x86)\Samsung\Settings\SettingsHibernateMonitor.exe [2014-04-21] (Samsung Electronics CO., LTD.)
      Task: {F67B6054-DAB3-40D9-AFF4-CC189A6B725E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
      Task: {FA3E95CA-BE91-4F8A-91CF-1C416D92DF09} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2016-02-24] (Samsung Electronics Co., Ltd.) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\{5351C598-7E87-2E7A-E949-7CB6E6D65AA2}.job =>  ==================== Atalhos ============================= (As entradas podem ser listadas para serem restauradas ou removidas.) ==================== Módulos Carregados (Whitelisted) ============== 2015-10-30 04:18 - 2015-10-30 04:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
      2016-03-05 18:55 - 2016-07-31 05:48 - 00173248 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
      2014-06-23 00:37 - 2014-02-13 06:07 - 00013824 _____ () C:\Program Files\Samsung\Samsung Link\JniSys.dll
      2016-03-08 13:15 - 2016-03-08 13:15 - 00515584 _____ () C:\Windows\Temp\sqlite-3.7.2-sqlitejdbc.dll
      2014-06-23 00:37 - 2014-02-13 06:07 - 02149376 _____ () C:\Program Files\Samsung\Samsung Link\scone_proxy.dll
      2014-06-23 00:37 - 2014-02-13 06:07 - 01630720 _____ () C:\Program Files\Samsung\Samsung Link\scone_stub.dll
      2013-12-20 23:25 - 2013-12-20 23:25 - 00036864 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\JNIInterface.dll
      2013-12-20 23:26 - 2013-12-20 23:26 - 00144384 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\ASFAPI.dll
      2013-12-20 23:27 - 2013-12-20 23:27 - 00018944 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\MediaDB_Manager.dll
      2013-10-21 21:52 - 2013-10-21 21:52 - 00030720 _____ () C:\WINDOWS\SYSTEM32\MediaDB64.dll
      2013-10-21 21:52 - 2013-10-21 21:52 - 00908800 _____ () C:\WINDOWS\SYSTEM32\ContentDirectoryPresenter64.dll
      2013-12-20 23:27 - 2013-12-20 23:27 - 00521728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\DMS_Manager.dll
      2013-07-23 07:19 - 2013-07-23 07:19 - 00049152 _____ () C:\WINDOWS\SYSTEM32\boost_date_time-vc90-mt-1_47.dll
      2013-07-23 07:19 - 2013-07-23 07:19 - 00299520 _____ () C:\WINDOWS\SYSTEM32\boost_serialization-vc90-mt-1_47.dll
      2013-07-23 07:19 - 2013-07-23 07:19 - 00016896 _____ () C:\WINDOWS\SYSTEM32\boost_system-vc90-mt-1_47.dll
      2013-07-23 07:19 - 2013-07-23 07:19 - 00058880 _____ () C:\WINDOWS\SYSTEM32\boost_thread-vc90-mt-1_47.dll
      2016-07-17 18:45 - 2016-07-01 01:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
      2016-07-17 18:45 - 2016-07-01 01:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
      2016-08-19 00:41 - 2016-08-19 00:41 - 00959168 _____ () C:\Users\eliete-ma1hotmail.co\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
      2014-06-23 00:35 - 2013-06-06 01:15 - 00288720 _____ () C:\Program Files\Bitcasa\ExplorerMenu.dll
      2014-06-23 00:36 - 2013-06-06 01:23 - 01645056 _____ () C:\Program Files\Bitcasa\bitcasaui.dll
      2016-04-21 12:44 - 2016-04-21 12:48 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
      2014-06-23 00:37 - 2014-02-13 06:07 - 00048640 _____ () C:\Program Files\Samsung\Samsung Link\JniIO.dll
      2016-03-08 12:51 - 2016-03-08 12:51 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
      2016-07-17 18:48 - 2016-07-01 00:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
      2016-07-17 18:49 - 2016-07-01 00:49 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
      2016-07-17 18:46 - 2016-07-01 00:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
      2016-07-17 18:46 - 2016-07-01 00:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
      2016-07-17 18:46 - 2016-07-01 00:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
      2016-07-17 18:46 - 2016-07-01 00:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
      2016-08-16 11:54 - 2016-08-16 12:00 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
      2016-08-16 11:54 - 2016-08-16 12:00 - 13475840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
      2016-06-03 22:02 - 2016-06-03 22:06 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
      2016-03-08 14:39 - 2016-03-08 14:41 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
      2013-12-11 04:46 - 2013-12-11 04:46 - 01114624 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DMSManager.dll
      2013-07-23 07:18 - 2013-07-23 07:18 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_serialization-vc90-mt-1_47.dll
      2013-07-23 07:18 - 2013-07-23 07:18 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_date_time-vc90-mt-1_47.dll
      2013-07-23 07:18 - 2013-07-23 07:18 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_system-vc90-mt-1_47.dll
      2013-07-23 07:18 - 2013-07-23 07:18 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_thread-vc90-mt-1_47.dll
      2013-10-21 21:48 - 2013-10-21 21:48 - 00707072 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ContentDirectoryPresenter.dll
      2013-12-11 04:46 - 2013-12-11 04:46 - 00102400 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\FolderCDP.dll
      2013-10-24 04:53 - 2013-10-24 04:53 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMCDP.dll
      2013-10-24 04:53 - 2013-10-24 04:53 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\Autobackup.dll
      2013-04-19 04:38 - 2013-04-19 04:38 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RosettaAllShare.dll
      2013-12-11 04:46 - 2013-12-11 04:46 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MetadataFramework.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\sqlite3.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MoodExtractor.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMImgExtractor.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AutoChaptering.dll
      2013-10-25 07:49 - 2013-10-25 07:49 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AudioExtractor.dll
      2013-12-11 04:45 - 2013-12-11 04:45 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoExtractor.dll
      2013-10-25 07:53 - 2013-10-25 07:53 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageExtractor.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\TextExtractor.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexpat.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoThumb.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00064000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ID3Driver.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RichInfoDriver.dll
      2013-10-25 07:53 - 2013-10-25 07:53 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ThumbnailMaker.dll
      2013-12-11 04:45 - 2013-12-11 04:45 - 00134144 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoMetadataDriver.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\SECMetaDriver.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\photoDriver.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avcodec-52.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avformat-52.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avutil-50.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\swscale-0.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\tag.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libThumbnail.dll
      2013-10-25 07:53 - 2013-10-25 07:53 - 01033728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageMagickWrapper.dll
      2013-10-25 07:48 - 2013-10-25 07:48 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libKeyFrame.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexif-12.dll.dll
      2013-02-14 07:42 - 2013-02-14 07:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\us.dll
      2014-04-21 21:42 - 2014-04-21 21:42 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
      2016-04-21 12:44 - 2016-04-21 12:48 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
      2016-04-21 12:44 - 2016-04-21 12:48 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
      2014-06-22 23:33 - 2013-09-16 17:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (Se uma entrada for incluída na fixlist, somente o ADS será removido.)
      ==================== Modo de Segurança (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)
      ==================== Associação (Whitelisted) =============== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.)
      ==================== Internet Explorer confiável/restrito =============== (Se uma entrada for incluída na fixlist, será removida do Registro.)
      ==================== Hosts Conteúdo: =============================== (Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.) 2013-08-22 10:25 - 2013-08-22 10:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts
      ==================== Outras Áreas ============================ (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-1917681920-812532136-750919602-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\eliete-ma1hotmail.co\Pictures\IMG_20150921_182627159.jpg
      DNS Servers: 192.168.0.1
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      Firewall do Windows está habilitado. ==================== MSCONFIG/TASK MANAGER ítens desabilitados == (Atualmente não há nenhuma correção automática para esta seção.)
      ==================== Regras do Firewall (Whitelisted) =============== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
      FirewallRules: [{DDD7837E-7A37-4DBF-826D-FE184A07CDCF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
      FirewallRules: [{4AE1FDFB-89F1-453B-A07F-66DD1298ACA8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
      FirewallRules: [{739B5276-70C3-4ED6-B69A-B23BF86B7296}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
      FirewallRules: [{EA45E8C2-33BD-41A5-AC72-BDA3ADD9B7FF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
      FirewallRules: [{DC75C338-D5CC-4294-85A9-4A813D39930C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
      FirewallRules: [{37C3CBAB-CA07-4D59-AE17-4FE821FFD840}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{B67A88C9-03B0-4F09-900B-C296770E43B8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{2316FB1B-97A4-4D1E-8167-461AC22BF96F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{863EC49D-E57D-4397-8BD6-35BABEF8661C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{8779CBCE-7B37-4748-8CCC-DF2285308BFE}] => (Allow) LPort=1900
      FirewallRules: [{A5C96F71-1AA7-4126-AD48-447A83289243}] => (Allow) LPort=7900
      FirewallRules: [{0BE568B1-2CC1-4A46-83D5-2A32E428EB91}] => (Allow) LPort=24234
      FirewallRules: [{55A43250-4040-4684-9E43-B48FFE417B45}] => (Allow) LPort=7679
      FirewallRules: [{B7837078-B61E-493F-85BB-AB101AC5B825}] => (Allow) LPort=7676
      FirewallRules: [{A88B72F0-5FF9-42D5-9BFF-089956630F30}] => (Allow) LPort=8643
      FirewallRules: [{535B8D4D-1AD0-4AFE-A296-0EE68622661E}] => (Allow) LPort=8743
      FirewallRules: [{E9A5593B-99AA-458D-9F6C-8308627033A1}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
      FirewallRules: [{44884B62-AFC5-4FFB-BE8E-35E90E328ACA}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
      FirewallRules: [{D5C983E8-4103-48FE-BEEF-3C8F6F000687}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
      FirewallRules: [{104AB3E6-4B17-4250-809B-AEB71407D275}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
      FirewallRules: [{C2D93898-98E2-421F-95A5-FC035D786EA1}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
      FirewallRules: [{739F8619-C00F-4498-AA60-A34191A77CDA}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
      FirewallRules: [{5CFD0C2D-B42B-4AA1-9083-A467A7ADD79C}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
      FirewallRules: [{3393BF31-6F22-4504-8A1A-F319E7539AE8}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
      FirewallRules: [UDP Query User{8B963389-55A7-4B0B-BEF8-F0AF69932004}C:\program files\samsung\samsung link\samsung link tray agent.exe] => (Block) C:\program files\samsung\samsung link\samsung link tray agent.exe
      FirewallRules: [TCP Query User{FD75AB9A-1467-4FB7-BB7B-879F00269EB7}C:\program files\samsung\samsung link\samsung link tray agent.exe] => (Block) C:\program files\samsung\samsung link\samsung link tray agent.exe
      FirewallRules: [{DC093757-C33F-43BA-BAD1-A4EFA8AD9B1A}] => (Allow) C:\Users\eliete-ma1hotmail.co\AppData\Local\Chromium\Application\chrome.exe
      FirewallRules: [{C53BFF10-2B29-4D25-85AB-51E18797A8B3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Pontos de Restauração ========================= 07-08-2016 11:57:29 Ponto de Verificação Agendado
      11-08-2016 14:12:43 Windows Update
      20-08-2016 11:34:44 Windows Update
      24-08-2016 14:54:04 JRT Pre-Junkware Removal ==================== Dispositivos Apresentando Falhas No Gerenciador =============
      ==================== Erros no Log de eventos: ========================= Erros em Aplicativos:
      ==================
      Error: (08/27/2016 09:31:50 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Eliete)
      Description: Falha na ativação do aplicativo Microsoft.Windows.Photos_8wekyb3d8bbwe!App com o erro: -2144927142. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (08/26/2016 10:24:14 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Eliete)
      Description: Falha na ativação do aplicativo Microsoft.Windows.Photos_8wekyb3d8bbwe!App com o erro: -2144927142. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (08/26/2016 10:24:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: O programa Microsoft.Photos.exe versão 1.0.1607.22006 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle Segurança e Manutenção. ID do Processo: 2e54 Hora de Início: 01d2000169f81d62 Hora de Término: 4294967295 Caminho do Aplicativo: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe ID do Relatório: eefba9c1-6bf4-11e6-8285-24f5aaee0493 Nome completo do pacote com falha: Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe ID do aplicativo relativo ao pacote com falha: App Error: (08/25/2016 11:25:29 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Eliete)
      Description: Falha na ativação do aplicativo Microsoft.Windows.Photos_8wekyb3d8bbwe!App com o erro: -2147023170. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (08/24/2016 06:37:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Eliete)
      Description: Falha na ativação do aplicativo Microsoft.Windows.Photos_8wekyb3d8bbwe!App com o erro: -2147023170. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (08/24/2016 04:18:34 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Eliete)
      Description: Falha na ativação do aplicativo Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App com o erro: -2144927141. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (08/24/2016 04:16:34 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Eliete)
      Description: O pacote Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy+App foi terminado porque levou muito tempo para ser suspenso. Error: (08/24/2016 04:13:32 PM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Erro no arquivo de manifesto ou de política C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL", na linha 1.
      Identidade do componente localizado no manifesto não corresponde à identidade do componente solicitado.
      A referência é UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      A definição é UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use o arquivo sxstrace.exe para obter um dignóstico detalhado. Error: (08/24/2016 03:29:27 PM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Erro no arquivo de manifesto ou de política C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL", na linha 1.
      Identidade do componente localizado no manifesto não corresponde à identidade do componente solicitado.
      A referência é UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      A definição é UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use o arquivo sxstrace.exe para obter um dignóstico detalhado. Error: (08/24/2016 02:54:45 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nome do aplicativo com falha: MicrosoftEdge.exe, versão: 11.0.10586.545, carimbo de data/hora: 0x57a1ba07
      Nome do módulo com falha: CoreUIComponents.dll, versão: 0.0.0.0, carimbo de data/hora: 0x5775df1f
      Código de exceção: 0xc0000005
      Deslocamento da falha: 0x00000000000782c7
      ID do processo com falha: 0x1808
      Hora de início do aplicativo com falha: 0x01d1fe2e608aa891
      Caminho do aplicativo com falha: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
      Caminho do módulo com falha: C:\WINDOWS\system32\CoreUIComponents.dll
      ID do Relatório: 0821217f-125c-4d92-b414-1a3400b2c16c
      Nome completo do pacote com falha: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe
      ID do aplicativo relativo ao pacote com falha: MicrosoftEdge
      Erros de Sistema:
      =============
      Error: (08/27/2016 09:31:49 AM) (Source: DCOM) (EventID: 10010) (User: Eliete)
      Description: App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca Error: (08/26/2016 10:24:02 PM) (Source: DCOM) (EventID: 10010) (User: Eliete)
      Description: App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca Error: (08/24/2016 04:18:34 PM) (Source: DCOM) (EventID: 10010) (User: Eliete)
      Description: App Error: (08/24/2016 04:16:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: Não foi possível iniciar o serviço Windows Presentation Foundation Font Cache 3.0.0.0 devido ao seguinte erro: 
      %%1053 = O serviço não respondeu à requisição de início ou controle em tempo hábil. Error: (08/24/2016 04:16:09 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
      Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço FontCache3.0.0.0. Error: (08/24/2016 04:13:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: O serviço Acesso a Dados de Usuário_c6630 foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 10000 milissegundos: Reiniciar o serviço. Error: (08/24/2016 04:13:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: O serviço Armazenamento de Dados de Usuário_c6630 foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 10000 milissegundos: Reiniciar o serviço. Error: (08/24/2016 04:13:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: O serviço Dados de Contato_c6630 foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 10000 milissegundos: Reiniciar o serviço. Error: (08/24/2016 04:13:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: O serviço Host de Sincronização_c6630 foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 10000 milissegundos: Reiniciar o serviço. Error: (08/23/2016 06:09:43 PM) (Source: DCOM) (EventID: 10016) (User: AUTORIDADE NT)
      Description: específico do aplicativoLocalAtivação{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}AUTORIDADE NTSISTEMAS-1-5-18LocalHost (Usando LRPC)Não DisponívelNão Disponível
      CodeIntegrity:
      ===================================
        Date: 2016-08-26 10:48:32.602
        Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.   Date: 2016-08-24 12:10:03.426
        Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.   Date: 2016-08-21 12:27:04.556
        Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.   Date: 2016-08-20 16:12:31.674
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.   Date: 2016-08-20 12:53:58.704
        Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.   Date: 2016-08-20 12:33:27.490
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.   Date: 2016-08-11 15:04:31.426
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.   Date: 2016-07-27 19:33:22.325
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.   Date: 2016-07-27 17:41:19.318
        Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.   Date: 2016-07-26 18:25:19.065
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
      ==================== Informações da Memória ===========================  Processador: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
      Percentagem de memória em uso: 51%
      RAM física total: 3969.83 MB
      RAM física disponível: 1912.3 MB
      Virtual Total: 6529.83 MB
      Virtual disponível: 3648.13 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:448.87 GB) (Free:384.13 GB) NTFS ==================== MBR & Tabela de Partições ================== ========================================================
      Disk: 0 (Size: 465.8 GB) (Disk ID: 723F0560) Partition: GPT. ==================== Fim de Addition.txt ============================  
    • Olá Elias,  Segue os logs solicitados anexos. Obrigado pela ajuda! JRT.txt Malwarebytes Anti-Malware.txt AdwCleaner[C0].txt
  • Today's Birthdays

    1. apollonet
      apollonet
      (58 years old)
    2. cmtejr
      cmtejr
      (32 years old)
    3. Czus
      Czus
      (26 years old)
    4. Eagle
      Eagle
      (23 years old)
    5. Ireudo
      Ireudo
      (43 years old)
  • Upcoming Events

    No upcoming events found