cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.7.27.104 Por Nicolas Coolman (2015/07/27)
~ iniciado por Usuario (Administrator) (2015/07/28 22:50:39)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Status da versão: Version OK
~ Modo: Scanner
~ Relatório: C:\Users\Usuario\Desktop\ZHPDiag.txt
~ Relatório: C:\Users\Usuario\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Inicialização do sistema: Normal (Normal boot)
~ Windows 8, 64-bit (Build 9200)

---\\ Navegadores Internet (3) - 1s
GCIE: Google Chrome v44.0.2403.107
MFIE: Mozilla Firefox 39.0 (x86 pt-BR) v39.0
MSIE: Internet Explorer v10.0.9200.17028

---\\ Informações sobre os produtos Windows (4) - 6s
~ Windows Server License Manager Script : OK
System - VBScript Engine not found
Windows Automatic Updates : OK (Demand)
Windows Activation Technologies : OK

---\\ Softwares de proteçao do sistema (2) - 2s
Avast Premier v10.2.2218
Malwarebytes Anti-Malware versão 2.0.2.1012

---\\ Softwares d'optimização do sistema (1) - 3s
CCleaner v4.09

---\\ Monitoramento dos softwares (2) - 3s
Adobe Flash Player 18 NPAPI
Adobe Reader XI

---\\ Informações sobre o sistema (6) - 0s
~ Operating System: Intel64 Family 6 Model 69 Stepping 1, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 6168.852 MB (69% free)
~ System Restore: Activé (Enable)
~ System drive C: has 380 GB free of 459 GB

---\\ Modo de conexão ao sistema (3) - 0s
~ Computer Name: ACER
~ User Name: Usuario
~ Logged in as Administrator

---\\ Enumeração das unidades dos discos (1) - 0s
~ Drive C: has 380 GB free of 459 GB (System)

---\\ Estado do Centro de Segurança do Windows (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Pesquisa particular de ficheiros genéricos (22) - 2s
[MD5.0E8E6463F81C80AFBED533E0F1F8895D] - (.Microsoft Corporation - Windows Explorer.) () -- C:\Windows\Explorer.exe [2391280]
[MD5.3A6209AC494296C24C2065CB4392B5F4] - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [51712]
[MD5.FE9AB232B56A12224E8A3F3F9878C9A3] - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) () -- C:\Windows\System32\Wininit.exe [132608]
[MD5.27E552632E6394DE0FA555EFDBA29A49] - (.Microsoft Corporation - Internet Extensions para Win32.) () -- C:\Windows\System32\wininet.dll [2239488]
[MD5.75DD70A14145499C9F7D903CF9A8C91B] - (.Microsoft Corporation - Aplicativo de Logon do Windows.) () -- C:\Windows\System32\Winlogon.exe [578048]
[MD5.9448F5740A037EC0C18F0E9177232DD0] - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) () -- C:\Windows\System32\sppcomapi.dll [273408]
[MD5.FE7FB9612D354EB41DF4F0FF5D6FB259] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [576512]
[MD5.A721FF570C2387E383BDDEA9632863C9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [25840]
[MD5.990B1BABE6E81FB18E65A87EBEFB1772] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [108544]
[MD5.339BFF85D788268752DA8C9644B188EE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [174080]
[MD5.431141C6859990824D17F71C30A78728] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [118784]
[MD5.7D87B5B6C7188D553E11B59DC7F0B111] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [71168]
[MD5.C9E9CBF73AFFBFE3E801EFB516787BA3] - (.Microsoft Corporation - Driver de porta i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [112640]
[MD5.3969B9C218DD3FAA9F4ED2FFC3651C02] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [145920]
[MD5.7A761AEE58658378BBA45D360F874CB0] - (.Microsoft Corporation - Minirdr SMB do Windows NT.) () -- C:\Windows\System32\drivers\MRxSmb.sys [370688]
[MD5.7CEC25C682D319D484630B3952C31A11] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [331776]
[MD5.7BE3EDFFA3216F989A6BDCB14795DD08] - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1939288]
[MD5.4563DAF8C6A740AD7F501E219BD10766] - (.Microsoft Corporation - Driver de porta paralela.) () -- C:\Windows\System32\drivers\Parport.sys [105984]
[MD5.A14D625C5AEE5FFE0F47D1A1D419FAAE] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [124928]
[MD5.B2A3AD74FF2E2FFA73AF2567108231B3] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [179712]
[MD5.73DC722CE5DF26D7638CE2446F2655C7] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [117248]
[MD5.78A5BBA3819FFFC62FFEC3E2220D102D] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) () -- C:\Windows\System32\drivers\volsnap.sys [327936]

---\\ Processos lançados (25) - 7s
[MD5.4F440DCDB7C8C14DEDDB1D63B94335D1] - (.GAS Tecnologia - G-Buster Browser Defense - Service.) -- C:\Program Files (x86)\GbPlugin\gbpsv.exe [579896] [PID.320]
[MD5.C6B6270CD764CD00A2E6BF04FA9F63CF] - (.IBM Corp. - RapportMgmtService.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2222360] [PID.508]
[MD5.54236E79A44F909612391C8A2D70D512] - (.Avast Software s.r.o. - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336] [PID.1332]
[MD5.C569E7F268C43D6C9C4D74EE2F06CCD8] - (.Avast Software s.r.o. - avast! firewall service.) -- C:\Program Files\AVAST Software\Avast\afwServ.exe [107448] [PID.1964]
[MD5.6E58CB683B2255787ECD568628C3C9E0] - (.ELAN Microelectronics Corp. - Elan Service.) -- C:\Program Files\Elantech\ETDService.exe [100752] [PID.1752]
[MD5.DDA8E5AD97231AB50B81FED04C28F64C] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648] [PID.2080]
[MD5.50672DB7AF32CD9D5AB829731256642C] - (.Intel(R) Corporation - Intel(R) Technology Access - Service.) -- C:\Program Files\Intel Corporation\Intel(R) Technology Access\IntelTechnologyAccessService.exe [93408] [PID.2128]
[MD5.5E57ABEAB076EBD32DDF795B59A09A12] - (.Acer Incorporate - LMSvc.) -- C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656] [PID.2180]
[MD5.55D9506A7EDEB8ED034971D45A534F88] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [487960] [PID.2260]
[MD5.EDA917548C58FA93F5357A9000D297BF] - (.GAS Tecnologia LTDA - GAS Tecnologia - Core.) -- C:\Program Files\Diebold\Warsaw\core.exe [847160] [PID.2408]
[MD5.46C430FE178028F7AD151B62EBA3EEC5] - (.Avast Software - AvastVirtualBox Interface.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896] [PID.3688]
[MD5.D0117917EB976A484B3A9E3AA7142108] - (.AVAST Software - avast! NG service.) -- C:\Program Files\AVAST Software\Avast\ng\ngservice.exe [171896] [PID.4224]
[MD5.23415E4EF5BBA82B794D50341921EC36] - (.ELAN Microelectronics Corp. - ETD Control Center.) -- C:\Program Files\Elantech\ETDCtrl.exe [2890640] [PID.3880]
[MD5.4F440DCDB7C8C14DEDDB1D63B94335D1] - (.GAS Tecnologia - G-Buster Browser Defense - Service.) -- C:\Program Files (x86)\GbPlugin\gbpsv.exe [579896] [PID.3992]
[MD5.7D6C36C00DDC3A6C3283ED656D0344BB] - (.ELAN Microelectronics Corp. - ETDTouch.) -- C:\Program Files\Elantech\ETDTouch.exe [84880] [PID.4708]
[MD5.D9D1F09C20694B5402B0E9835C93E9C4] - (.IBM Corp. - RapportService.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe [2980120] [PID.3952]
[MD5.372429F96B0D09CF86A1D37437621D34] - (.Acer Incorporate - LMEvent.) -- C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe [442920] [PID.3256]
[MD5.C08B0B46E2BF431FF0D5AC8C6142C5BA] - (.ELAN Microelectronics Corp. - ETD Control Center Helper.) -- C:\Program Files\Elantech\ETDCtrlHelper.exe [2248592] [PID.2584]
[MD5.6A2963D0105D039891E96EE312F52215] - (.Acer Incorporate - LMTray.) -- C:\Program Files\Acer\Acer Launch Manager\LMTray.exe [428072] [PID.5388]
[MD5.6DDA13FB28B620FEE52E0E616F4E7B70] - (.Realtek Semiconductor - Gerenciador de áudio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784] [PID.6040]
[MD5.EDA917548C58FA93F5357A9000D297BF] - (.GAS Tecnologia LTDA - GAS Tecnologia - Core.) -- C:\Program Files\Diebold\Warsaw\core.exe [847160] [PID.5640]
[MD5.65C6AA484AD2287D20541C7735989437] - (.Avast Software s.r.o. - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe [5515496] [PID.5796]
[MD5.687C6930244387AA5E479B16DEFE4175] - (.Beijing WatchData System Co., Ltd. - WatchSAFE Background v3.4.) -- C:\Windows\SysWOW64\WatchData\Watchdata Brazil CSP v1.0\BBCertM32.exe [59440] [PID.4148]
[MD5.346A684AF87AE8A0F31E7101D5C4A313] - (.Sony Corporation - Media Check Tool.) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [2725400] [PID.4016]
[MD5.4F9DD96AECDC12373D4203253D665C6D] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896] [PID.3956]

---\\ Google Chrome, Arranque,Pesquisa,Extensões (G0,G1,G2 (19) - 3s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://4.bp.blogspot.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ajax.googleapis.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://illiweb.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.forumpcbrasil.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com.br/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com/
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] AdBlock
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [mkeabchhfifpaaoefpockjhaphjmoapp] GBBD Banco do Brasil
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (P2,M0,M1,M2,M3) (21) - 8s
M0 - MFSP: prefs.js [Usuario - 10e0ymyg.default-1394480445891] https://www.google.com/?trackid=sp-006
P2 - EXT FILE: (...) -- C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\10e0ymyg.default-1394480445891\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\10e0ymyg.default-1394480445891\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT FILE: (...) -- C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\10e0ymyg.default-1394480445891\searchplugins\google-avast.xml
P2 - EXT FILE: (...) -- C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\10e0ymyg.default-1394480445891\searchplugins\Google.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\buscape.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mercadolivre.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\twitter.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia-br.xml
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo-br.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
P2 - FPN: [HKCU] [gastecnologia.com.br/sf/bb] - (.GAS Tecnologia.) -- C:\Users\Usuario\AppData\Local\GAS Tecnologia\GBBD\npsf_bb.dll
P2 - FPN: [HKCU] [gastecnologia.com.br/sf/bb64] - (.GAS Tecnologia.) -- C:\Users\Usuario\AppData\Local\GAS Tecnologia\GBBD\npsf_bb_64.dll
P2 - FPN: [HKCU] [gastecnologia.com.br/sf/gas64] - (...) -- C:\Users\Usuario\AppData\Local\GAS Tecnologia\GBBD\npsf_gas_64.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.51.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.51.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

---\\ Internet Explorer, Arranque, Pesquisa, URLSearchHook( gancho de URL), Phishing (R0,R1,R3,R4) (16) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer, Gestão do Proxy (R5) (3) - 1s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Análise das linhas F0, F1, F2, F3 - Ficheiros ini, Carregamento Automático de programas (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.)

---\\ Redireção do ficheiro Hosts (O1) (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (20)

---\\ Browser Helper Objects do navegador (O2) (5) - 1s
O2 - BHO: (no name) [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Orphean)
O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.Avast Software s.r.o. - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
O2 - BHO: G-Buster Browser Defense [64Bits] - {C41A1C0E-EA6C-11D4-B1B8-444553540000} (Orphean)
O2 - BHO: G-Buster Browser Defense Itaú Unibanco [64Bits] - {C41A1C0E-EA6C-11D4-B1B8-444553540008} (Orphean)
O2 - BHO: (no name) [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} (Orphean)

---\\ Barras do Internet Explorer (O3) (2) - 1s
O3 - Toolbar: 0x2D4A524F3756532D41547A786E7484D7 - [HKCU]{4F524A2D-5637-2D53-4154-7A786E7484D7} . (...) -- (.not file.)
O3 - Toolbar: 0xB1C218236549D4119B18009027A5CD4F - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} . (...) -- (.not file.)

---\\ Aplicações iniciadas por registo & pastas (O4) (12) - 2s
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gerenciador de áudio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [Diebold - Warsaw] . (.GAS Tecnologia LTDA - GAS Tecnologia - Core.) -- C:\Program Files\Diebold\Warsaw\core.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.Avast Software s.r.o. - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe
O4 - HKLM\..\Wow6432Node\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe
O4 - HKLM\..\Wow6432Node\Run: [wdbraz_certm] . (.Beijing WatchData System Co., Ltd. - WatchSAFE Background v3.4.) -- C:\Windows\SysWOW64\WatchData\Watchdata Brazil CSP v1.0\BBCertM32.exe
O4 - HKLM\..\Wow6432Node\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKUS\S-1-5-21-3064860665-2106470997-2649600080-1001\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe

---\\ Alteração Dominio/Clientes DNS (017) (6) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 200.195.159.100 200.195.159.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 200.195.159.100 200.195.159.101

---\\ Lista dos serviços NT não Microsoft e não desativados (023) (17) - 6s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Avast Antivirus (avast! Antivirus) . (.Avast Software s.r.o. - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall (avast! Firewall) . (.Avast Software s.r.o. - avast! firewall service.) - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: CCDMonitorService (CCDMonitorService) . (.Acer Incorporated - CCD Monitor Service.) - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Elan Service (ETDService) . (.ELAN Microelectronics Corp. - Elan Service.) - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Gbp Service (GbpSv) . (.GAS Tecnologia - G-Buster Browser Defense - Service.) - C:\Program Files (x86)\GbPlugin\gbpsv.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Technology Access Service (Intel(R) TechnologyAccessService) . (.Intel(R) Corporation - Intel(R) Technology Access - Service.) - C:\Program Files\Intel Corporation\Intel(R) Technology Access\IntelTechnologyAccessService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) . (.Acer Incorporate - LMSvc.) - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: @c:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) . (.Nero AG - NeroUpdate.) - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: PMBDeviceInfoProvider (PMBDeviceInfoProvider) . (.Sony Corporation - Device Information Provider.) - C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
O23 - Service: Rapport Management Service (RapportMgmtService) . (.IBM Corp. - RapportMgmtService.) - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Warsaw Technology (Warsaw Technology) . (.GAS Tecnologia LTDA - GAS Tecnologia - Core.) - C:\Program Files\Diebold\Warsaw\core.exe

---\\ Tarefas planificadas automaticamente (039) (21) - 8s
O39 - APT: Orphean - (...) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [902]
O39 - APT: Orphean - (...) -- C:\Windows\Tasks\AutoKMS.job [284] =>HackTool.AutoKMS
O39 - APT: Orphean - (...) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1082]
O39 - APT: Orphean - (...) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1086]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Adobe Acrobat Update Task [3886]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3790]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\ALU [3626]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\ALUAgent [4402]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\AutoKMS [2894] =>HackTool.AutoKMS
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\avast! Emergency Update [4182]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-3064860665-2106470997-2649600080-1001 [3274]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2776]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3822]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4058]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\HPCustParticipation HP Deskjet 2050 J510 series [3622]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 [3718]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon [3476]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Launch Manager [2904]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Pokki [3228]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Power Management [2914]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{32C664C5-3C97-4930-AD6C-D1EC28E62F41} [3150]

---\\ Software instalados (042) (88) - 41s
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner
O42 - Logiciel: ETDWare PS/2-X64 11.6.23.203_WHQL - (.ELAN Microelectronic Corp..) [HKLM][64Bits] -- Elantech
O42 - Logiciel: WinRAR 5.21 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: Acer Recovery Management - (.Acer Incorporated.) [HKLM][64Bits] -- {07F2005A-8CAC-4A4B-83A2-DA98A722CA61}
O42 - Logiciel: Warsaw 1.5.1.8886 64 bits - (.GAS Tecnologia.) [HKLM][64Bits] -- {20E60725-16C8-4FB9-8BC2-AF92C5F8D06D}_is1
O42 - Logiciel: HP Deskjet 2050 J510 series Software básico do dispositivo - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {2DCBB45E-AA03-4089-87E7-EC17E606D738}
O42 - Logiciel: MergeModule_x64 - (.Sony Corporation.) [HKLM][64Bits] -- {3D576235-F0CE-4B50-A9C6-0775B9E50B63}
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {44B72151-611E-429D-9765-9BA093D7E48A}
O42 - Logiciel: Broadcom Card Reader Driver Installer - (.Broadcom Corporation.) [HKLM][64Bits] -- {67AA948F-8D83-4566-B84A-7CAABCF64E3F}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: HP Deskjet 2050 J510 series Estudo de aprimoramento de produtos - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {8D71EFB0-B1EF-4478-92D2-A65DB23AC460}
O42 - Logiciel: Acer Power Management - (.Acer Incorporated.) [HKLM][64Bits] -- {91F52DE4-B789-42B0-9311-A349F10E5479}
O42 - Logiciel: Acer Launch Manager - (.Acer Incorporated.) [HKLM][64Bits] -- {C18D55BD-1EC6-466D-B763-8EEDDDA9100E}
O42 - Logiciel: Broadcom NetLink Controller - (.Broadcom Corporation.) [HKLM][64Bits] -- {D1D7ED66-5C08-40A0-AEC0-B6DF977697BB}
O42 - Logiciel: Shared C Run-time for x64 - (.McAfee.) [HKLM][64Bits] -- {EF79C448-6946-4D71-8134-03407888C054}
O42 - Logiciel: Intel(R) Technology Access - (.Intel Corporation.) [HKLM][64Bits] -- {FE4EC25E-CCE4-477C-80B4-C6B351EE1BC6}
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI
O42 - Logiciel: Avast Premier - (.AVAST Software.) [HKLM][64Bits] -- Avast
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM][64Bits] -- HP Photo Creations
O42 - Logiciel: Malwarebytes Anti-Malware versão 2.0.2.1012 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Ferramentas do Visual Studio 2005 para Office Second Edition Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Visual Studio 2005 Tools for Office Runtime
O42 - Logiciel: Mozilla Firefox 39.0 (x86 pt-BR) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 39.0 (x86 pt-BR)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService
O42 - Logiciel: Norton Online Backup ARA - (.Symantec Corporation.) [HKLM][64Bits] -- NARA
O42 - Logiciel: Proteção de Terminal Trusteer - (.Trusteer.) [HKLM][64Bits] -- Rapport_msi
O42 - Logiciel: Spotify - (.Spotify AB.) [HKLM][64Bits] -- Spotify
O42 - Logiciel: Visual Studio Tools for the Office system 3.0 Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- Visual Studio Tools for the Office system 3.0 Runtime
O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent wildgames Master Uninstall =>.WildTangent
O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM][64Bits] -- WTA-15fe5bb5-876f-418d-9be9-5c1b19a76bb3 =>.WildTangent
O42 - Logiciel: Dora's World Adventure - (.WildTangent.) [HKLM][64Bits] -- WTA-2d29eaca-19a2-41ea-b8a0-b149622366b2 =>.WildTangent
O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-3b75d74f-4dee-43ef-985b-0d36c109b021 =>.WildTangent
O42 - Logiciel: Peggle Nights - (.WildTangent.) [HKLM][64Bits] -- WTA-455d511b-04d1-48d9-9313-9517cef8beb4 =>.WildTangent
O42 - Logiciel: Tales of Lagoona - (.WildTangent.) [HKLM][64Bits] -- WTA-6400e493-3dcf-471b-a5e7-72239dacbd7a =>.WildTangent
O42 - Logiciel: Mystery P.I. - Curious Case of Counterfeit Cove - (.WildTangent.) [HKLM][64Bits] -- WTA-6e024c47-6b7b-48ed-bd17-80268fb39a75 =>.WildTangent
O42 - Logiciel: Cradle Of Egypt Collector's Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-73bc6594-8b84-4ecc-82a8-ef30daaf149b =>.WildTangent
O42 - Logiciel: Delicious: Emily's Childhood Memories Premium Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-cd248b06-76f5-4f60-a699-70485188c4dc =>.WildTangent
O42 - Logiciel: Jewel Match 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-e237140d-9f4d-4201-9ee0-cad98d0b1444 =>.WildTangent
O42 - Logiciel: The Chronicles of Emerland Solitaire - (.WildTangent.) [HKLM][64Bits] -- WTA-f8cfc0c8-d28f-4560-9948-b72a4d5895aa =>.WildTangent
O42 - Logiciel: Yahoo Search Set - (.Yahoo Inc..) [HKLM][64Bits] -- Yahoo! SearchSet
O42 - Logiciel: Nero RescueAgent Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {0B311221-05A5-4766-8D03-7A6446794156}
O42 - Logiciel: Nero Launcher - (.Nero AG.) [HKLM][64Bits] -- {0E4630AF-0AB7-440E-A978-1A78FC4F43B9}
O42 - Logiciel: PMB_ModeEditor - (.Sony Corporation.) [HKLM][64Bits] -- {19FEBF46-AE2C-45C7-BF9F-E254A4B3E717}
O42 - Logiciel: Rapport - (.Trusteer.) [HKLM][64Bits] -- {1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}
O42 - Logiciel: Office Addin 2003 - (.Acer.) [HKLM][64Bits] -- {1FCC073B-CC01-4443-AD20-E559F66E6E83}
O42 - Logiciel: Skype™ 7.6 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Java 8 Update 51 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218051F0}
O42 - Logiciel: Qualcomm Atheros WiFi Driver Installation - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33}
O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App =>.WildTangent
O42 - Logiciel: MergeModule_x86 - (.Sony Corporation.) [HKLM][64Bits] -- {306CBA87-E890-4FBB-9AB8-E65C96D352B2}
O42 - Logiciel: clear.fi SDK- Movie 2 - (.CyberLink Corp..) [HKLM][64Bits] -- {35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}
O42 - Logiciel: Módulo de Segurança - Banco do Brasil - (...) [HKLM][64Bits] -- {36386dc9-8543-4b12-ae6b-220fd52f19f3}_is1
O42 - Logiciel: Identity Card - (.Acer Incorporated.) [HKLM][64Bits] -- {3D9CB654-99AD-4301-89C6-0D12A790767C}
O42 - Logiciel: Norton Online Backup - (.Symantec Corporation.) [HKLM][64Bits] -- {40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}
O42 - Logiciel: Intel(R) Update Manager - (.Intel Corporation.) [HKLM][64Bits] -- {43FA4AC8-46F8-423F-96FD-9A7D67048F1C}
O42 - Logiciel: Nero BackItUp 12 Essentials OEM.a01 - (.Nero AG.) [HKLM][64Bits] -- {4CA8F973-6377-4ABF-9ED5-CC2323B3C000}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Nero Update - (.Nero AG.) [HKLM][64Bits] -- {65BB0407-4CC8-4DC7-952E-3EEFDF05602A}
O42 - Logiciel: Office Addin - (.Acer.) [HKLM][64Bits] -- {6D2BBE1D-E600-4695-BA37-0B0E605542CC}
O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM][64Bits] -- {6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}
O42 - Logiciel: WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer =>.WildTangent
O42 - Logiciel: HP Deskjet 2050 J510 series Ajuda - (.Hewlett Packard.) [HKLM][64Bits] -- {7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}
O42 - Logiciel: PMB_ServiceUploader - (.Sony Corporation.) [HKLM][64Bits] -- {8E5861CA-9B65-488B-972E-405AD03EBC7C}
O42 - Logiciel: Visual Studio Tools for the Office system 3.0 Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- {8FB53850-246A-3507-8ADE-0060093FFEA6}
O42 - Logiciel: Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949 - (.Microsoft Corporation.) [HKLM][64Bits] -- {8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258
O42 - Logiciel: BB Token Admin Tool - (.Watchdata Technologies Pte., Ltd..) [HKLM][64Bits] -- {95A34656-CD4A-45A0-BAB8-AB950EFCBEBF}
O42 - Logiciel: PlayMemories Home - (.Sony Corporation.) [HKLM][64Bits] -- {9BC57F80-FBCF-463C-B69F-09DEC3A4612B}
O42 - Logiciel: Nero RescueAgent - (.Nero AG.) [HKLM][64Bits] -- {A2D43081-CF7B-4637-A9F3-E2651AA5C4A8}
O42 - Logiciel: AcerCloud Portal - (.Acer Incorporated.) [HKLM][64Bits] -- {A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {ABC88553-8770-4B97-B43E-5A90647A5B63}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824147215}
O42 - Logiciel: Adobe Reader XI (11.0.12) - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AB0000000001}
O42 - Logiciel: clear.fi Photo - (.Acer Incorporated.) [HKLM][64Bits] -- {B5AD89F2-03D3-4206-8487-018298007DD0}
O42 - Logiciel: Nero Core Components - (.Nero AG.) [HKLM][64Bits] -- {BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
O42 - Logiciel: Nero ControlCenter Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {C994C746-C6D0-4EBA-B09E-DF7B18381B69}
O42 - Logiciel: AcerCloud Docs - (.Acer Incorporated.) [HKLM][64Bits] -- {CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}
O42 - Logiciel: Nero BackItUp - (.Nero AG.) [HKLM][64Bits] -- {DA2D3078-A58C-45E8-8EE0-18B8BE6B34F7}
O42 - Logiciel: clear.fi Media - (.Acer Incorporated.) [HKLM][64Bits] -- {E9AF1707-3F3A-49E2-8345-4F2D629D0876}
O42 - Logiciel: clear.fi SDK - Video 2 - (.CyberLink Corp..) [HKLM][64Bits] -- {EBA33CAD-E071-48d5-A168-FBA4EEB42E93}
O42 - Logiciel: Live Updater - (.Acer Incorporated.) [HKLM][64Bits] -- {EE26E302-876A-48D9-9058-3129E5B99999}
O42 - Logiciel: Nero BackItUp Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {EF0D1292-8FC1-41BE-9740-DBC134F66415}
O42 - Logiciel: Intel(R) Technology Access - (.Intel Corporation.) [HKLM][64Bits] -- {efc54997-dfa9-44b1-afac-3a7ac4f45730}
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573}
O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU][64Bits] -- Dropbox

---\\ HKCU & HKLM Software Keys (77) - 41s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AdwCleaner
HKLM\SOFTWARE\Wow6432Node\AutoHelpDesk
HKLM\SOFTWARE\Wow6432Node\AVAST Software
HKLM\SOFTWARE\Wow6432Node\Clearfi
HKLM\SOFTWARE\Wow6432Node\CyberLink
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware (Trial)
HKLM\SOFTWARE\Wow6432Node\McAfee
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Nero
HKLM\SOFTWARE\Wow6432Node\Norton
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\OEM
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros WiFi Driver Installation
HKLM\SOFTWARE\Wow6432Node\Realtek
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\RocketLife
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\Sony Corporation
HKLM\SOFTWARE\Wow6432Node\Symantec
HKLM\SOFTWARE\Wow6432Node\Trusteer
HKLM\SOFTWARE\Wow6432Node\Visan
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\WildTangent
HKLM\SOFTWARE\Wow6432Node\Yahoo
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\AutoHelpDesk
HKCU\SOFTWARE\AVAST Software
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\Cyberlink
HKCU\SOFTWARE\Dropbox
HKCU\SOFTWARE\Elantech
HKCU\SOFTWARE\GbAs
HKCU\SOFTWARE\GbPlugin
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Hewlett-Packard
HKCU\SOFTWARE\HP
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Malwarebytes' Anti-Malware
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\OEM
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Sony Corporation
HKCU\SOFTWARE\SYNCJM
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\Trusteer
HKCU\SOFTWARE\Visan
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Amazon
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft

---\\ Conteúdo das pastas Programs/ProgramFiles/ProgramData/AppData (O43) (186) - 31s
O43 - CFD: 2013/11/14 10:00:16 - [] D -- C:\Program Files (x86)\Acer
O43 - CFD: 2014/03/07 15:33:55 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2013/11/14 09:53:38 - [] D -- C:\Program Files (x86)\Amazon
O43 - CFD: 2014/03/07 16:23:56 - [] D -- C:\Program Files (x86)\Brazil
O43 - CFD: 2015/07/15 12:47:40 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/03/25 17:10:27 - [] HD -- C:\Program Files (x86)\Diebold
O43 - CFD: 2015/03/25 17:10:27 - [] HD -- C:\Program Files (x86)\GAS Tecnologia
O43 - CFD: 2015/07/28 12:49:46 - [] AD -- C:\Program Files (x86)\GbPlugin
O43 - CFD: 2015/07/28 12:49:08 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2014/03/18 09:43:26 - [] D -- C:\Program Files (x86)\HP
O43 - CFD: 2014/03/18 09:43:35 - [] D -- C:\Program Files (x86)\HP Photo Creations
O43 - CFD: 2013/11/14 09:57:19 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 2015/02/25 09:27:16 - [] D -- C:\Program Files (x86)\Intel
O43 - CFD: 2014/08/05 15:36:14 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/07/15 12:46:21 - [] D -- C:\Program Files (x86)\Java
O43 - CFD: 2014/06/04 19:14:14 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Malware
O43 - CFD: 2014/04/14 21:48:22 - [0] D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 2014/11/15 21:08:43 - [0] D -- C:\Program Files (x86)\Microsoft
O43 - CFD: 2014/03/07 16:13:30 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2014/03/07 16:16:19 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2015/03/18 16:20:31 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 2014/03/07 16:16:18 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 2014/03/07 16:16:18 - [] D -- C:\Program Files (x86)\Microsoft Sync Framework
O43 - CFD: 2014/03/07 16:16:32 - [] D -- C:\Program Files (x86)\Microsoft Synchronization Services
O43 - CFD: 2014/03/07 16:13:55 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD: 2014/03/07 16:16:18 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/07/14 12:53:21 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 2015/07/14 12:53:21 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 2014/03/07 16:16:46 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2013/08/12 21:52:24 - [] D -- C:\Program Files (x86)\Nero
O43 - CFD: 2013/11/14 09:55:25 - [] D -- C:\Program Files (x86)\Norton Online Backup ARA
O43 - CFD: 2013/11/14 09:55:22 - [] D -- C:\Program Files (x86)\NortonInstaller
O43 - CFD: 2013/11/14 09:40:18 - [] D -- C:\Program Files (x86)\Qualcomm Atheros
O43 - CFD: 2013/11/14 09:44:55 - [] D -- C:\Program Files (x86)\Realtek
O43 - CFD: 2013/08/12 21:33:57 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/07/08 17:32:08 - [] RD -- C:\Program Files (x86)\Skype
O43 - CFD: 2015/03/09 11:31:23 - [] D -- C:\Program Files (x86)\Sony
O43 - CFD: 2013/11/14 09:50:02 - [] D -- C:\Program Files (x86)\Spotify
O43 - CFD: 2013/11/14 09:55:29 - [] D -- C:\Program Files (x86)\Symantec
O43 - CFD: 2013/11/14 09:45:18 - [0] HD -- C:\Program Files (x86)\Temp
O43 - CFD: 2015/03/16 18:32:51 - [] D -- C:\Program Files (x86)\Trusteer
O43 - CFD: 2013/08/12 21:48:19 - [] D -- C:\Program Files (x86)\WildGames
O43 - CFD: 2013/08/12 21:48:24 - [] D -- C:\Program Files (x86)\WildTangent Games
O43 - CFD: 2014/08/05 15:36:28 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2013/11/14 15:17:42 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2013/11/14 15:17:42 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2012/07/26 05:13:01 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 2012/07/26 05:12:59 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2014/04/03 17:58:59 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2012/07/26 05:13:01 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2012/07/26 05:12:59 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2015/07/14 17:59:10 - [] D -- C:\Program Files (x86)\Yahoo!
O43 - CFD: 2012/07/26 05:13:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2014/04/03 17:59:47 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2013/11/14 10:09:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
O43 - CFD: 2014/04/03 17:58:34 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/01/26 23:40:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
O43 - CFD: 2014/03/07 16:23:57 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BB Token Tool
O43 - CFD: 2014/03/07 15:43:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 2013/08/12 21:48:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2014/03/07 15:48:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2014/03/18 09:43:35 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
O43 - CFD: 2015/02/25 09:27:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
O43 - CFD: 2015/07/15 12:47:02 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2012/07/26 05:13:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2014/06/04 19:14:14 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 2014/03/07 16:17:05 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2015/03/18 16:21:30 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2013/08/12 21:52:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
O43 - CFD: 2013/11/14 09:55:29 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
O43 - CFD: 2015/03/09 11:38:19 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home
O43 - CFD: 2015/07/14 12:59:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Proteção de Terminal Trusteer
O43 - CFD: 2014/03/07 16:17:05 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
O43 - CFD: 2014/11/25 13:00:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 2015/07/14 18:50:54 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2013/04/21 12:36:51 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2012/07/26 04:52:57 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/02/28 10:16:09 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2013/11/14 09:59:09 - [] D -- C:\ProgramData\Acer
O43 - CFD: 2014/03/12 12:33:59 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2012/07/26 04:22:08 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2014/03/07 16:07:31 - [] D -- C:\ProgramData\AVAST Software
O43 - CFD: 2015/03/25 19:16:24 - [] D -- C:\ProgramData\boost_interprocess
O43 - CFD: 2013/11/14 09:57:15 - [] D -- C:\ProgramData\CLSK
O43 - CFD: 2014/04/16 21:22:20 - [] D -- C:\ProgramData\CyberLink
O43 - CFD: 2014/03/07 14:27:58 - [0] SHD -- C:\ProgramData\Dados de Aplicativos
O43 - CFD: 2012/07/26 04:22:08 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2014/03/07 14:27:58 - [0] SHD -- C:\ProgramData\Documentos
O43 - CFD: 2012/07/26 04:22:08 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/07/25 12:23:11 - [] D -- C:\ProgramData\GAS Tecnologia
O43 - CFD: 2015/07/28 11:45:08 - [] D -- C:\ProgramData\GbPlugin
O43 - CFD: 2014/03/18 09:43:04 - [] D -- C:\ProgramData\HP
O43 - CFD: 2014/03/18 09:43:34 - [] D -- C:\ProgramData\HP Photo Creations
O43 - CFD: 2013/11/14 09:57:19 - [] D -- C:\ProgramData\install_clap
O43 - CFD: 2015/02/25 17:38:17 - [] D -- C:\ProgramData\Intel
O43 - CFD: 2015/02/25 09:27:16 - [] D -- C:\ProgramData\Intel(R) Update Manager
O43 - CFD: 2014/04/14 21:48:22 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 2015/07/14 18:41:37 - [] D -- C:\ProgramData\McAfee
O43 - CFD: 2014/03/07 14:27:58 - [0] SHD -- C:\ProgramData\Menu Iniciar
O43 - CFD: 2015/03/18 16:41:23 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2014/03/07 16:18:01 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2014/03/07 14:27:58 - [0] SHD -- C:\ProgramData\Modelos
O43 - CFD: 2014/03/07 15:37:26 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2013/08/12 21:52:10 - [] D -- C:\ProgramData\Nero
O43 - CFD: 2014/03/17 14:32:17 - [] D -- C:\ProgramData\Norton
O43 - CFD: 2013/11/14 09:55:22 - [] D -- C:\ProgramData\NortonInstaller
O43 - CFD: 2013/11/14 09:52:39 - [] D -- C:\ProgramData\OEM
O43 - CFD: 2014/03/07 14:32:32 - [] D -- C:\ProgramData\OEM_YAHOO
O43 - CFD: 2015/07/15 12:48:14 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2015/03/29 17:07:49 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 2013/08/12 21:35:09 - [] D -- C:\ProgramData\PRICache
O43 - CFD: 2013/11/14 09:40:11 - [] D -- C:\ProgramData\Qualcomm Atheros
O43 - CFD: 2014/03/07 16:04:41 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/07/08 17:32:26 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2015/04/28 12:52:59 - [] D -- C:\ProgramData\Sony Corporation
O43 - CFD: 2012/07/26 04:22:08 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2014/03/07 15:37:30 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2013/11/14 09:55:29 - [] D -- C:\ProgramData\Symantec
O43 - CFD: 2015/03/25 19:11:29 - [] D -- C:\ProgramData\Temp
O43 - CFD: 2012/07/26 04:22:08 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2015/03/16 18:27:43 - [] D -- C:\ProgramData\Trusteer
O43 - CFD: 2014/03/18 09:43:34 - [] D -- C:\ProgramData\Visan
O43 - CFD: 2013/08/12 21:48:24 - [] D -- C:\ProgramData\WildTangent
O43 - CFD: 2014/05/15 14:14:30 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2014/03/07 16:16:31 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 2013/11/14 09:44:52 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 2015/07/15 12:47:40 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 2014/03/07 16:16:52 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 2013/08/12 21:52:10 - [] D -- C:\Program Files (x86)\Common Files\Nero
O43 - CFD: 2013/11/14 09:37:36 - [] D -- C:\Program Files (x86)\Common Files\postureAgent
O43 - CFD: 2012/07/26 05:13:01 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2014/11/25 13:00:41 - [] D -- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 2015/07/19 18:58:03 - [0] D -- C:\Program Files (x86)\Common Files\Sony Shared
O43 - CFD: 2014/03/07 16:13:42 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2014/11/13 21:30:03 - [] D -- C:\Users\Usuario\AppData\Roaming\Adobe
O43 - CFD: 2014/03/07 16:09:26 - [] D -- C:\Users\Usuario\AppData\Roaming\AVAST Software
O43 - CFD: 2014/04/16 21:22:29 - [] D -- C:\Users\Usuario\AppData\Roaming\CyberLink
O43 - CFD: 2015/07/28 14:03:54 - [] D -- C:\Users\Usuario\AppData\Roaming\Dropbox
O43 - CFD: 2015/07/28 14:03:46 - [] D -- C:\Users\Usuario\AppData\Roaming\DropboxMaster
O43 - CFD: 2015/02/04 17:09:32 - [] D -- C:\Users\Usuario\AppData\Roaming\Google
O43 - CFD: 2014/03/25 13:32:16 - [] D -- C:\Users\Usuario\AppData\Roaming\HpUpdate
O43 - CFD: 2014/06/16 18:08:37 - [] D -- C:\Users\Usuario\AppData\Roaming\Identities
O43 - CFD: 2014/03/07 16:31:49 - [] D -- C:\Users\Usuario\AppData\Roaming\Macromedia
O43 - CFD: 2014/04/14 21:48:33 - [0] D -- C:\Users\Usuario\AppData\Roaming\Malwarebytes
O43 - CFD: 2015/07/26 15:57:29 - [] SD -- C:\Users\Usuario\AppData\Roaming\Microsoft
O43 - CFD: 2014/03/07 16:24:46 - [] D -- C:\Users\Usuario\AppData\Roaming\Mozilla
O43 - CFD: 2015/07/28 22:03:25 - [] D -- C:\Users\Usuario\AppData\Roaming\Skype
O43 - CFD: 2015/03/09 11:37:12 - [] D -- C:\Users\Usuario\AppData\Roaming\Sony Corporation
O43 - CFD: 2015/05/27 16:04:25 - [] D -- C:\Users\Usuario\AppData\Roaming\WinRAR
O43 - CFD: 2015/07/28 22:51:34 - [] D -- C:\Users\Usuario\AppData\Roaming\ZHP
O43 - CFD: 2015/07/14 18:39:17 - [] D -- C:\Users\Usuario\AppData\Local\Adobe
O43 - CFD: 2014/03/10 10:51:09 - [] D -- C:\Users\Usuario\AppData\Local\Amazon_Services_LLC
O43 - CFD: 2014/03/07 16:19:31 - [] D -- C:\Users\Usuario\AppData\Local\Apps
O43 - CFD: 2014/03/07 16:19:32 - [] D -- C:\Users\Usuario\AppData\Local\assembly
O43 - CFD: 2015/03/10 13:35:26 - [] D -- C:\Users\Usuario\AppData\Local\clear.fi
O43 - CFD: 2014/04/16 21:22:28 - [] D -- C:\Users\Usuario\AppData\Local\Cyberlink
O43 - CFD: 2014/03/07 14:30:32 - [0] SHD -- C:\Users\Usuario\AppData\Local\Dados de Aplicativos
O43 - CFD: 2015/07/21 18:49:52 - [0] D -- C:\Users\Usuario\AppData\Local\Deployment
O43 - CFD: 2015/07/10 16:45:11 - [] D -- C:\Users\Usuario\AppData\Local\Diagnostics
O43 - CFD: 2015/05/27 13:44:02 - [0] D -- C:\Users\Usuario\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2014/09/15 17:02:51 - [] D -- C:\Users\Usuario\AppData\Local\GAS Tecnologia
O43 - CFD: 2015/07/28 11:52:28 - [] D -- C:\Users\Usuario\AppData\Local\Google
O43 - CFD: 2014/03/07 14:30:32 - [0] SHD -- C:\Users\Usuario\AppData\Local\Histórico
O43 - CFD: 2014/03/18 09:46:07 - [] D -- C:\Users\Usuario\AppData\Local\HP
O43 - CFD: 2014/03/07 15:57:02 - [] D -- C:\Users\Usuario\AppData\Local\Intel_Corporation
O43 - CFD: 2014/03/10 16:17:55 - [] D -- C:\Users\Usuario\AppData\Local\Macromedia
O43 - CFD: 2015/07/26 15:57:29 - [] D -- C:\Users\Usuario\AppData\Local\Microsoft
O43 - CFD: 2014/06/30 16:49:10 - [] D -- C:\Users\Usuario\AppData\Local\Microsoft Help
O43 - CFD: 2014/03/07 16:24:46 - [] D -- C:\Users\Usuario\AppData\Local\Mozilla
O43 - CFD: 2015/03/16 15:52:53 - [0] D -- C:\Users\Usuario\AppData\Local\MusicPlayer
O43 - CFD: 2014/03/07 14:32:19 - [] D -- C:\Users\Usuario\AppData\Local\Packages
O43 - CFD: 2014/03/07 16:27:14 - [] D -- C:\Users\Usuario\AppData\Local\Programs
O43 - CFD: 2014/11/25 13:08:13 - [] D -- C:\Users\Usuario\AppData\Local\Skype
O43 - CFD: 2014/04/16 21:22:29 - [] D -- C:\Users\Usuario\AppData\Local\Software =>PUP.Optional.Boxore
O43 - CFD: 2015/07/28 22:50:43 - [] D -- C:\Users\Usuario\AppData\Local\Temp
O43 - CFD: 2014/03/07 14:30:32 - [0] SHD -- C:\Users\Usuario\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/03/16 18:33:05 - [] D -- C:\Users\Usuario\AppData\Local\Trusteer
O43 - CFD: 2014/03/07 14:31:11 - [0] D -- C:\Users\Usuario\AppData\Local\VirtualStore
O43 - CFD: 2012/07/26 05:13:00 - [] RD -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2012/07/26 05:13:00 - [] RD -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2014/08/05 15:40:08 - [] RD -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/05/06 12:39:24 - [] D -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
O43 - CFD: 2012/07/26 05:13:00 - [] D -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2014/08/05 15:40:08 - [] RD -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2013/11/14 09:36:13 - [] RD -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/02/28 10:16:09 - [] D -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ Lista dos drivers do sistema (SDL) (O58) (68) - 15s
O58 - SDL:2012/07/26 02:00:49 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [106736]
O58 - SDL:2014/04/24 18:58:14 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\48230029.sys [119512]
O58 - SDL:2012/07/26 02:00:49 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [492272]
O58 - SDL:2012/07/26 02:00:48 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [340720]
O58 - SDL:2012/07/26 02:00:49 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [184048]
O58 - SDL:2012/07/26 02:00:49 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [76016]
O58 - SDL:2012/07/26 02:00:49 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [258288]
O58 - SDL:2012/07/26 02:00:48 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [26352]
O58 - SDL:2012/07/26 02:00:49 A . (.PMC-Sierra, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [104688]
O58 - SDL:2012/07/26 02:00:48 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [108272]
O58 - SDL:2015/04/22 12:59:39 A . (...) -- C:\Windows\System32\drivers\aswHwid.sys [29168]
O58 - SDL:2015/04/22 12:59:01 A . (.Avast Software s.r.o. - avast! Keyboard Filter Driver.) -- C:\Windows\System32\drivers\aswKbd.sys [28144]
O58 - SDL:2015/04/22 12:59:39 A . (.Avast Software s.r.o. - avast! File System Minifilter for Windows 2.) -- C:\Windows\System32\drivers\aswMonFlt.sys [89944]
O58 - SDL:2015/04/22 12:58:34 A . (.Avast Software s.r.o. - avast! Filtering NDIS driver.) -- C:\Windows\System32\drivers\aswNdisFlt.sys [449896]
O58 - SDL:2015/04/22 12:59:38 A . (.Avast Software s.r.o. - avast! WFP Redirect Driver.) -- C:\Windows\System32\drivers\aswRdr2.sys [93528]
O58 - SDL:2015/04/22 12:59:39 A . (...) -- C:\Windows\System32\drivers\aswRvrt.sys [65736]
O58 - SDL:2015/04/22 12:59:02 A . (.Avast Software s.r.o. - avast! Virtualization Driver.) -- C:\Windows\System32\drivers\aswSnx.sys [1047320]
O58 - SDL:2015/06/29 11:00:06 A . (.Avast Software s.r.o. - avast! self protection module.) -- C:\Windows\System32\drivers\aswsp.sys [442264]
O58 - SDL:2015/04/22 12:59:39 A . (.Avast Software s.r.o. - Stream Filter.) -- C:\Windows\System32\drivers\aswStm.sys [137288]
O58 - SDL:2015/04/22 12:59:39 A . (...) -- C:\Windows\System32\drivers\aswVmm.sys [272248]
O58 - SDL:2013/03/11 01:03:26 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\Windows\System32\drivers\athw8x.sys [3776000]
O58 - SDL:2013/04/10 15:00:54 A . (.Broadcom Corporation - Broadcom SD 3.0 Driver.) -- C:\Windows\System32\drivers\bScsiSDa.sys [84688]
O58 - SDL:2013/04/21 12:00:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [533224]
O58 - SDL:2013/04/22 04:09:52 A . (.ELAN Microelectronics Corp. - ETD Kernel Center.) -- C:\Windows\System32\drivers\ETD.sys [367504]
O58 - SDL:2013/04/21 12:00:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3265256]
O58 - SDL:2014/03/07 15:47:40 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\fshjundp.sys [422216]
O58 - SDL:2012/07/26 02:00:52 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64752]
O58 - SDL:2014/03/07 15:42:30 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\hsbyyzod.sys [422216]
O58 - SDL:2012/07/26 02:00:52 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [411888]
O58 - SDL:2013/07/09 14:03:42 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [4445152]
O58 - SDL:2014/03/07 15:33:53 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\iibhoeiq.sys [422216]
O58 - SDL:2012/07/26 02:00:52 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [45296]
O58 - SDL:2013/07/09 14:10:21 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [452088]
O58 - SDL:2013/03/27 02:40:52 A . (.Broadcom Corporation - Broadcom NetLink (TM) Gigabit Ethernet NDIS.) -- C:\Windows\System32\drivers\k57nd60a.sys [455888]
O58 - SDL:2013/01/10 00:23:14 A . (.Acer Incorporated - Launch Manager Wireless Driver.) -- C:\Windows\System32\drivers\LMDriver.sys [21360]
O58 - SDL:2012/07/26 02:00:52 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [108784]
O58 - SDL:2012/07/26 02:00:52 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [92400]
O58 - SDL:2012/07/26 02:00:52 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [116976]
O58 - SDL:2012/07/26 02:00:52 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [81136]
O58 - SDL:2014/05/12 07:25:56 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [25816]
O58 - SDL:2014/05/12 07:26:00 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [91352]
O58 - SDL:2014/10/15 14:52:44 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [122584]
O58 - SDL:2012/07/26 02:00:52 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [51952]
O58 - SDL:2012/07/26 02:00:52 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [353008]
O58 - SDL:2014/03/07 15:52:22 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\mfkocegn.sys [422216]
O58 - SDL:2012/07/26 02:00:55 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [64240]
O58 - SDL:2014/05/12 07:26:14 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [64216]
O58 - SDL:2014/10/30 22:30:22 A . (.Intel Corporation - Intel(R) Technology Access Filter Driver.) -- C:\Windows\System32\drivers\ndisrfl.sys [41688]
O58 - SDL:2014/10/30 22:30:22 A . (.Intel Corporation - Intel(R) Technology Access TAP Driver.) -- C:\Windows\System32\drivers\nettap630.sys [67800]
O58 - SDL:2012/07/26 02:00:55 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [52464]
O58 - SDL:2012/07/26 02:00:55 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150256]
O58 - SDL:2012/07/26 02:00:55 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168176]
O58 - SDL:2013/01/10 00:23:14 A . (.Acer Incorporated - RadioShim.) -- C:\Windows\System32\drivers\RadioShim.sys [15704]
O58 - SDL:2015/06/02 18:41:06 A . (.IBM Corp. - RapportHades64.) -- C:\Windows\System32\drivers\RapportHades64.sys [121432]
O58 - SDL:2015/06/02 18:41:06 A . (.IBM Corp. - RapportKE.) -- C:\Windows\System32\drivers\RapportKE64.sys [376184]
O58 - SDL:2013/03/19 09:21:10 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [3363016]
O58 - SDL:2012/07/26 05:11:43 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040]
O58 - SDL:2012/07/26 02:00:55 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44784]
O58 - SDL:2012/07/26 02:00:56 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81648]
O58 - SDL:2012/07/26 02:00:55 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [30960]
O58 - SDL:2013/05/08 17:23:38 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\TeeDriverx64.sys [99800]
O58 - SDL:2012/07/26 02:00:58 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19184]
O58 - SDL:2012/07/26 02:00:58 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [164080]
O58 - SDL:2012/07/26 02:00:58 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [322800]
O58 - SDL:2014/03/07 15:44:46 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\watinqcy.sys [422216]
O58 - SDL:2014/03/07 15:45:46 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\wcbyjzaj.sys [422216]
O58 - SDL:2014/03/07 15:37:51 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\zpnavwbm.sys [422216]
O58 - SDL:2015/06/08 17:12:17 A . (.Basil - WinDivert (web: http://reqrypt.org/windiver.) -- C:\Windows\System32\WinDivert64.sys [38104]

---\\ Últimos ficheiros alterados ou criados (Utilizador) (061) (2) - 19s
O61 - LFC: 2015/07/28 22:38:46 A . (..) -- C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849]
O61 - LFC: 2015/07/24 13:14:47 A . (..) -- C:\Users\Usuario\AppData\Local\Adobe\Acrobat\11.0\UserCache.bin [116319]

---\\ Associações Shell Spawning (O67) (1) - 0s
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos.) -- C:\Windows\System32\eventvwr.exe

---\\ Menu de inicialização Internet (068) (12) - 1s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe

---\\ Pesquisa de infeção nos navegadores da Internet (SBI) (069) (2) - 25s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} - (Google) - http://www.google.com/

---\\ Listagem dos serviços iniciados pelo Svchost (SSS) (O83) (34) - 6s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Serviço de Experiência com Aplicativo.) -- C:\Windows\System32\aelupsvc.dll [190976]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\Windows\System32\certprop.dll [149504]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\Windows\System32\certprop.dll [149504]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\Windows\system32\srvsvc.dll [309248]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [1366016]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\ikeext.dll [1160192]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acess.) -- C:\Windows\System32\rasauto.dll [99840]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\Windows\System32\rasmans.dll [358400]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [107520]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) -- C:\Windows\System32\sens.dll [62976]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\Windows\System32\ipnathlp.dll [438784]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft(R) Windo.) -- C:\Windows\System32\tapisrv.dll [305664]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [3286528]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) -- C:\Windows\System32\qmgr.dll [826368]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [565760]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\Windows\System32\iphlpsvc.dll [894464]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\Windows\system32\seclogon.dll [30720]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\Windows\System32\appinfo.dll [70144]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\Windows\system32\iscsiexe.dll [151552]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\Windows\System32\eapsvc.dll [105472]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\Windows\system32\schedsvc.dll [1285632]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [219648]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Serviço Agendador de Classes de Multimídia.) -- C:\Windows\system32\mmcss.dll [80896]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\Windows\System32\browser.dll [134144]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho.) -- C:\Windows\System32\SessEnv.dll [291328]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\Windows\System32\wercplsupport.dll [84992]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\Windows\system32\kmsvc.dll [97792]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [190976]
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\Windows\system32\wlidsvc.dll [1964544]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\Windows\system32\themeservice.dll [47104]
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\Windows\System32\DeviceSetupManager.dll [207872]
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede.) -- C:\Windows\System32\ncasvc.dll [161792]
O83 - Search Svchost Services: SystemEventsBroker (SystemEventsBroker) . (.Microsoft Corporation - Agente de Eventos do Sistema.) -- C:\Windows\System32\SystemEventsBrokerServer.dll [180224]

---\\ Lista das exceções do FireWall (FirewallRules) (O87) (31) - 7s
O87 - FAEL: "WMP-In-UDP-x86" [In-None-P17-FALSE] .(...) -- C:\ProgramFiles(x86)\Windows Media Player\wmplayer.exe
O87 - FAEL: "WMP-Out-UDP-x86" [Out-None-P17-FALSE] .(...) -- C:\ProgramFiles(x86)\Windows Media Player\wmplayer.exe
O87 - FAEL: "WMP-Out-TCP-x86" [Out-None-P6-FALSE] .(...) -- C:\ProgramFiles(x86)\Windows Media Player\wmplayer.exe
O87 - FAEL: "WMPNSS-In-UDP-NoScope" [In-None-P17-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-Out-UDP-NoScope" [Out-None-P17-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-In-TCP-NoScope" [In-None-P6-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-Out-TCP-NoScope" [Out-None-P6-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-In-UDP" [In-None-P17-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-Out-UDP" [Out-None-P17-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-In-TCP" [In-None-P6-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "WMPNSS-Out-TCP" [Out-None-P6-FALSE] .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
O87 - FAEL: "{7FF2A163-C17C-4D68-A970-66EF24C64390}" [In-None-P6-TRUE] .(.Spotify Ltd - Spotify.) -- C:\Program Files (x86)\Spotify\spotify.exe
O87 - FAEL: "{5EB331FF-3F24-4532-85BE-D4946136A44A}" [In-None-P17-TRUE] .(.Spotify Ltd - Spotify.) -- C:\Program Files (x86)\Spotify\spotify.exe
O87 - FAEL: "{0D32DAB5-DE69-430D-955B-00722DFB5B22}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
O87 - FAEL: "{C80705D0-A32A-4376-B75F-E00A5E3418E3}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
O87 - FAEL: "{0CCFA6C8-297E-47DC-9EA1-3B96C3CE40A6}" [In-None-P6-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
O87 - FAEL: "{D980A466-E8D3-4815-8A20-560C990AEAAE}" [In-None-P17-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
O87 - FAEL: "{331DAD00-FBCD-4A20-A9B3-08849F530CD1}" [In-None-P6-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
O87 - FAEL: "{FC764AD0-B402-496B-A447-D9363115BEB7}" [In-None-P17-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
O87 - FAEL: "{D31726FA-AA82-4EEA-ADF2-F9E69CC4BC89}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\clear.fi SDK21\Video\VideoPlayer.exe
O87 - FAEL: "{C0EDB26A-E8BE-4EF6-8974-CEEB28F9E25A}" [In-None-P6-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
O87 - FAEL: "{4144D705-21F1-41DF-8FB1-9D18DDB3E5CD}" [In-None-P17-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
O87 - FAEL: "{CCBA4A85-C5E5-4D6C-B287-0CFAE840E1E4}" [In-None-P6-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
O87 - FAEL: "{9D8229F0-19BF-40CC-A53C-5F960C1B133A}" [In-None-P17-TRUE] .(.acer - DLNA Stack App.) -- C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
O87 - FAEL: "{184E2EDE-A044-486B-B586-DDBEF4113210}" [In-None-P6-TRUE] .(.Acer Cloud Technology - AcerCloud Client.) -- C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe
O87 - FAEL: "{6CDB41E4-722C-47B8-B19E-AFE774B5389E}" [In-None-P17-TRUE] .(.Acer Cloud Technology - AcerCloud Client.) -- C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe
O87 - FAEL: "{DE09F086-6215-4532-A826-E20BC8822662}" [In-None-P17-TRUE] .(.Sony Corporation - Browser.) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBBrowser.exe
O87 - FAEL: "{9C8417BE-EFD9-4B07-8D6F-30FC12476709}" [In-None-P6-TRUE] .(.Sony Corporation - Browser.) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBBrowser.exe
O87 - FAEL: "{03029884-01F5-4DF0-B5B1-3FE7D2C51D44}" [In-None-P6-TRUE] .(.GAS Tecnologia LTDA - GAS Tecnologia - Core.) -- C:\Program Files\Diebold\Warsaw\core.exe
O87 - FAEL: "{71E3862E-C84C-4E14-B5C0-96370B08EDE4}" [In-None-P6-TRUE] .(.AVAST Software - avast! NG front end.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
O87 - FAEL: "{34184772-24EF-4B3C-B3D9-B411CDE22CA0}" [In-None-P17-TRUE] .(.AVAST Software - avast! NG front end.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe

---\\ Pesquisa dos pacotes WindowsInstaller (WIS) (O93) (NTFS) (1) - 16s
[MD5.] [WIS][2015/02/14 17:03:05] (.APN, LLC - Ask.com ® - Install Builder.) -- C:\Windows\Installer\2311da9c.msi [516096] =>PUP.Optional.Bandoo

---\\ Scâner Aditional (088) (4) - 0s
C:\Windows\Tasks\AutoKMS.job =>HackTool.AutoKMS
C:\Windows\System32\Tasks\AutoKMS =>HackTool.AutoKMS
C:\Users\Usuario\AppData\Local\Software =>PUP.Optional.Boxore
C:\Windows\Installer\2311da9c.msi =>PUP.Optional.Bandoo

---\\ Resumo dos elementos encontrados na sua estação de trabalho (3) - 0s
http://www.nicolascoolman.fr/trojan-autokms/ =>HackTool.AutoKMS
http://www.nicolascoolman.fr/adware-boxore/ =>PUP.Optional.Boxore
http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo

~ End of the scan, 20702 items in 350 seconds (751)(0)()

Publicité


Signaler le contenu de ce document

Publicité