cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.9.7.137 Por Nicolas Coolman (2015/09/7)
~ iniciado por Teco (Administrator) (2015/09/14 18:40:00)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Status da versão: Rede de arquivo
~ Modo: Scanner
~ Relatório: C:\Users\Teco\Desktop\ZHPDiag.txt
~ Relatório: C:\Users\Teco\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Inicialização do sistema: Normal (Normal boot)
Windows 8.1 Single Language, 64-bit (Build 9600)

---\\ Navegadores Internet (2) - 0s
GCIE: Google Chrome v45.0.2454.85
MSIE: Internet Explorer v11.0.9600.17801

---\\ Informações sobre os produtos Windows (3) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ Softwares de proteçao do sistema (1) - 1s
Windows Defender (Activate)

---\\ Monitoramento dos softwares (2) - 2s
Adobe Flash Player 11 Plugin
Adobe Reader X MUI

---\\ Informações sobre o sistema (6) - 0s
~ Operating System: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4075.256 MB (67% free)
~ System Restore: Activé (Enable)
~ System drive C: has 54 GB free of 190 GB

---\\ Modo de conexão ao sistema (3) - 0s
~ Computer Name: SOARES-PC
~ User Name: Teco
~ Logged in as Administrator

---\\ Enumeração das unidades dos discos (2) - 0s
~ Drive C: has 54 GB free of 190 GB (System)
~ Drive D: has 148 GB free of 264 GB

---\\ Estado do Centro de Segurança do Windows (13) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Pesquisa particular de ficheiros genéricos (24) - 3s
[MD5.C10A66189DC8C090E7C84873EDCEBC88] - (.Microsoft Corporation - Windows Explorer.) () -- C:\WINDOWS\Explorer.exe [2501368] ©
[MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [54784] ©
[MD5.A570A64292214C43E0BA50E6A72A6380] - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) () -- C:\WINDOWS\System32\Wininit.exe [145920] ©
[MD5.F0289B3A341429117696F0279DA977B6] - (.Microsoft Corporation - Internet Extensions para Win32.) () -- C:\WINDOWS\System32\wininet.dll [2352128] ©
[MD5.EC498BAE1F0D3E0E401C963F8D76C437] - (.Microsoft Corporation - Aplicativo de Logon do Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [572416] ©
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) () -- C:\WINDOWS\System32\sppcomapi.dll [447488] ©
[MD5.0B082D6D7A53D91678E7409DD145E89C] - (.Microsoft Corporation - DLL da API de cliente DNS.) () -- C:\WINDOWS\System32\dnsapi.dll [657920] ©
[MD5.205BDB00F4C032AF45A6BFD18EA7886C] - (.Microsoft Corporation - DLL da API de cliente DNS.) () -- C:\WINDOWS\Syswow64\dnsapi.dll [498688] ©
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [563200] ©
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [26464] ©
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [88576] ©
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [164352] ©
[MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [134144] ©
[MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [76800] ©
[MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - (.Microsoft Corporation - Driver de porta i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [108544] ©
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [142848] ©
[MD5.31233271EDE50D1BBB220F78AFA60486] - (.Microsoft Corporation - Minirdr SMB do Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [405504] ©
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [282624] ©
[MD5.7F68063A5A0461E02BC860CE0E6BFDDC] - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2025792] ©
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Driver de porta paralela.) () -- C:\WINDOWS\System32\drivers\Parport.sys [94208] ©
[MD5.1BD3022FD6E450B00DE560265638FD2A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [112640] ©
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Micros.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [195584] ©
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [107520] ©
[MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [310080] ©

---\\ Processos lançados (1) - 0s
[MD5.277789334263C78BD58231766AD7C015] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Teco\AppData\Roaming\ZHP\ZHPDiag3.exe [1923072] [PID.840] ©

---\\ Google Chrome, Arranque,Pesquisa,Extensões (20) - 1s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ajax.aspnetcdn.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://answers.microsoft.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://i.answers.microsoft.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://i2.answers.microsoft.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://i3.answers.microsoft.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://nexus.ensighten.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients2.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.googleapis.com/
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Docs
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [ijepgjdjkdbopbnaopmlmobimmhjklhd] Yahoo!
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (2) - 0s
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ©
P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ©

---\\ Internet Explorer, Arranque, Pesquisa, Phishing (15) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer, Gestão do Proxy (5) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Análise das linhas, Carregamento Automático de programas (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.)

---\\ Redireção do ficheiro Hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (19)

---\\ Browser Helper Objects do navegador (1) - 0s
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL ©

---\\ Aplicações iniciadas por registo & pastas (20) - 1s
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe ©
O4 - HKLM\..\Run: [SpaceSoundPro] C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe (.not file.) =>PUP.Optional.SpaceSoundPro
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Teco\AppData\Local\Facebook\Update\FacebookUpdate.exe ©
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe ©
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Teco\AppData\Local\Microsoft\OneDrive\OneDrive.exe ©
O4 - HKCU\..\Run: [RGSC] . (.Take-Two Interactive Software, Inc. - RGSCLauncher.) -- C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe ©
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe ©
O4 - HKCU\..\Run: [YeaInstaller] C:\Users\Teco\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_168.exe (.not file.)
O4 - HKCU\..\Run: [-] c:\users\teco\appdata\local\temp\00030620\popwnd.exe (.not file.)
O4 - HKCU\..\Run: [Pritc] C:\Users\Teco\AppData\Local\Temp\00060\iiiii2.exe (.not file.)
O4 - HKCU\..\Run: [Yeaplayer] . (.PZ - Yeaplayer.) -- C:\Program Files (x86)\Yeaplayer\Yeaplayermd.exe
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Teco\AppData\Local\Facebook\Update\FacebookUpdate.exe ©
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe ©
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Teco\AppData\Local\Microsoft\OneDrive\OneDrive.exe ©
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [RGSC] . (.Take-Two Interactive Software, Inc. - RGSCLauncher.) -- C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe ©
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe ©
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [YeaInstaller] C:\Users\Teco\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_168.exe (.not file.)
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [-] c:\users\teco\appdata\local\temp\00030620\popwnd.exe (.not file.)
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [Pritc] C:\Users\Teco\AppData\Local\Temp\00060\iiiii2.exe (.not file.)
O4 - HKUS\S-1-5-21-4208416025-2343778504-1709046129-1001\..\Run: [Yeaplayer] . (.PZ - Yeaplayer.) -- C:\Program Files (x86)\Yeaplayer\Yeaplayermd.exe

---\\ Atalhos globais Startup (1) - 1s
O4 - GS\Programs [Public]: Ajuda.lnk . (...) C:\Program Files (x86)\Probit Software\Easy Driver Pro\EasyDriverPro.chm =>PUP.Optional.ProbitSoftware

---\\ Alteração Dominio/Clientes DNS (6) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.143.172,82.163.142.174
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = homestation
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.143.172,82.163.142.174
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = homestation

---\\ Protocolo adicional (23) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office\Office15\MSOSB.DLL ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL ©

---\\ Serviços NT não Microsoft e não desativados (4) - 1s
O23 - Service: Application Manager 3.57.4713165 (AppMgr3.57.4713165) . (...) - C:\ProgramData\AppMgr3.57.4713165\AppMgr.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
O23 - Service: The Screen Snapshot Service (TheScreenSnapshotService) . (...) - C:\Program Files (x86)\ScreenSnapshotTool\1.0.1.10820\ScreenShotServ.exe (.not file.)
O23 - Service: @C:\Program Files (x86)\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (.not file.)

---\\ Tarefas planificadas automaticamente (33) - 16s
[MD5.1BA1AB4141A92EB34DA99F1249CA2D4D] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [257416] ©
[MD5.C6D3BB61E24F66EB976C6CC55346B5F2] [APT] [ASUS InstantOn Config] (.ASUS.) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [1196416] ©
[MD5.DB0C938BC311B31CF90C13821AE682B3] [APT] [ASUS Live Update] (.ASUSTeK Computer Inc..) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [1559936] ©
[MD5.0BC5A4142F38A6BB35DECD01A2BC2ED7] [APT] [ASUS P4G] (.ASUS.) -- C:\Program Files\ASUS\P4G\BatteryLife.exe [1018240] ©
[MD5.C570FD825751F7805CE226F68C4605DE] [APT] [ASUS Splendid ACMON] (.ASUS.) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [54488] ©
[MD5.B07086D59443DAC6A668D691B27B968C] [APT] [ASUS Splendid ColorU] (.ASUSTeK Computer Inc..) -- C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [176240] ©
[MD5.922C047998B7761F3DF048BE8A92BAB5] [APT] [ASUS Touchpad Launcher (x64)] (.AsusTek.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18232] ©
[MD5.97432AB9F1B3B3E63E778C1E69E71E91] [APT] [ASUS USB Charger Plus] (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [1124032] ©
[MD5.7529BF17445E16315A95B450CE985C11] [APT] [AsusVibeSchedule] (.Copyright (C) 2010.) -- C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [1957040]
[MD5.C746CD166372F3C6F364B62F2C2C8B20] [APT] [AutoKMSCustom] (.CODYQX4.) -- C:\Windows\AutoKMS\AutoKMS.exe [3738624] =>HackTool.AutoKMS
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001Core] (.Facebook Inc..) -- C:\Users\Teco\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] ©
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001UA] (.Facebook Inc..) -- C:\Users\Teco\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] ©
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004Core] (.Facebook Inc..) -- C:\Users\Casa\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] ©
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004UA] (.Facebook Inc..) -- C:\Users\Casa\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [902] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001Core - (.Facebook Inc..) -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001Core.job [922] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001UA - (.Facebook Inc..) -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001UA.job [944] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004Core - (.Facebook Inc..) -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004Core.job [922] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004UA - (.Facebook Inc..) -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004UA.job [944] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater [3790] ©
O39 - APT: ASUS InstantOn Config - (.ASUS.) -- C:\WINDOWS\System32\Tasks\ASUS InstantOn Config [2990] ©
O39 - APT: ASUS Live Update - (.ASUSTeK Computer Inc..) -- C:\WINDOWS\System32\Tasks\ASUS Live Update [3114] ©
O39 - APT: ASUS P4G - (.ASUS.) -- C:\WINDOWS\System32\Tasks\ASUS P4G [3052] ©
O39 - APT: ASUS Splendid ACMON - (.ASUS.) -- C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON [2988] ©
O39 - APT: ASUS Splendid ColorU - (.ASUSTeK Computer Inc..) -- C:\WINDOWS\System32\Tasks\ASUS Splendid ColorU [3004] ©
O39 - APT: ASUS Touchpad Launcher (x64) - (.AsusTek.) -- C:\WINDOWS\System32\Tasks\ASUS Touchpad Launcher (x64) [3542] ©
O39 - APT: ASUS USB Charger Plus - (.ASUSTek Computer Inc..) -- C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus [3024] ©
O39 - APT: AsusVibeSchedule - (.Copyright (C) 2010.) -- C:\WINDOWS\System32\Tasks\AsusVibeSchedule [3268]
O39 - APT: AutoKMSCustom - (.CODYQX4.) -- C:\WINDOWS\System32\Tasks\AutoKMSCustom [3238] =>HackTool.AutoKMS
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001Core - (.Facebook Inc..) -- C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001Core [3440] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001UA - (.Facebook Inc..) -- C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1001UA [3790] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004Core - (.Facebook Inc..) -- C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004Core [3436] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004UA - (.Facebook Inc..) -- C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4208416025-2343778504-1709046129-1004UA [3786] ©

---\\ Software instalados (76) - 9s
O42 - Logiciel: Windows Driver Package - ASUS (ATP) Mouse (01/10/2013 1.0.0.170) - (.ASUS.) [HKLM][64Bits] -- 4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5 ©
O42 - Logiciel: Primary Color - (.Primary Color.) [HKLM][64Bits] -- Primary Color =>PUP.Optional.PrimaryColor
O42 - Logiciel: WinRAR 5.01 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver ©
O42 - Logiciel: ASUS Screen Saver - (.ASUS.) [HKLM][64Bits] -- {0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2} ©
O42 - Logiciel: Advanced ScreenSnapshot 1.0 - (.qiusheng xie.) [HKLM][64Bits] -- {61FFE1F9-137D-4c31-A181-3415FCAA5946}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} ©
O42 - Logiciel: Microsoft Access MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Excel MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft PowerPoint MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Publisher MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Outlook MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Word MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft InfoPath MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft DCF MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft OneNote MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Groove MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-0416-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Lync MUI (Portuguese (Brazil)) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-0416-1000-0000000FF1CE} ©
O42 - Logiciel: ASUS Power4Gear Hybrid - (.ASUS.) [HKLM][64Bits] -- {9B6239BF-4E85-4590-8D72-51E30DB1A9AA} ©
O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} ©
O42 - Logiciel: Shared C Run-time for x64 - (.McAfee.) [HKLM][64Bits] -- {EF79C448-6946-4D71-8134-03407888C054} ©
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {F4404AFD-2EF3-40C1-8C09-29E5F3B6972B} ©
O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin ©
O42 - Logiciel: Advanced RAR Repair v1.2 - (...) [HKLM][64Bits] -- Advanced RAR Repair v1.2
O42 - Logiciel: AsusVibe2.0 - (.ASUSTEK.) [HKLM][64Bits] -- Asus Vibe2.0 ©
O42 - Logiciel: ASUS WebStorage Sync Agent - (.ASUS Cloud Corporation.) [HKLM][64Bits] -- ASUS WebStorage ©
O42 - Logiciel: DAEMON Tools Lite - (.Disc Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite ©
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome ©
O42 - Logiciel: IHMC CmapTools v6.01 - (.Institute for Human & Machine Cognition.) [HKLM][64Bits] -- IHMC CmapTools v6.01 ©
O42 - Logiciel: ASUSDVD - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B} ©
O42 - Logiciel: PhotoScape - (...) [HKLM][64Bits] -- PhotoScape
O42 - Logiciel: PhraseProfessor 1.10.0.24 - (.PhraseProfessor.) [HKLM][64Bits] -- PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic
O42 - Logiciel: Revo Uninstaller 1.95 - (.VS Revo Group.) [HKLM][64Bits] -- Revo Uninstaller ©
O42 - Logiciel: ss8 - (.smart-saverplus.) [HKLM][64Bits] -- ss8 =>PUP.Optional.CrossRider
O42 - Logiciel: Pro Evolution Soccer 2015 - (...) [HKLM][64Bits] -- UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player ©
O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent wildgames Master Uninstall © =>.WildTangent
O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM][64Bits] -- WTA-547575f4-d1b2-4bea-b2dc-c541af028336 © =>.WildTangent
O42 - Logiciel: Azteca - (.WildTangent.) [HKLM][64Bits] -- WTA-745e2108-2859-48c8-90b6-b8731ac20dcf © =>.WildTangent
O42 - Logiciel: Peggle - (.WildTangent.) [HKLM][64Bits] -- WTA-9907f5a1-0908-4265-98b6-194faeb46f2e © =>.WildTangent
O42 - Logiciel: Tales of Lagoona - (.WildTangent.) [HKLM][64Bits] -- WTA-b4bfd7bb-484d-4512-bebf-60164ec5f174 © =>.WildTangent
O42 - Logiciel: Cut the Rope - (.WildTangent.) [HKLM][64Bits] -- WTA-d9de84be-303a-49c6-8a2b-aef2d49634fd © =>.WildTangent
O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-e60b8531-1c16-4aa7-a47a-951c4601b5a4 © =>.WildTangent
O42 - Logiciel: 1.0.0.1 - (...) [HKLM][64Bits] -- Yeaplayer
O42 - Logiciel: Rockstar Games Social Club - (.Rockstar Games.) [HKLM][64Bits] -- {08B3869E-D282-424C-9AFC-870E04A4BA14} ©
O42 - Logiciel: ASUS Splendid Video Enhancement Technology - (.ASUS.) [HKLM][64Bits] -- {0969AF05-4FF6-4C00-9406-43599238DE0D} ©
O42 - Logiciel: ASUS LifeFrame3 - (.ASUS.) [HKLM][64Bits] -- {1DBD1F12-ED93-49C0-A7CC-56CBDE488158} ©
O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} ©
O42 - Logiciel: Skype™ 7.3 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} ©
O42 - Logiciel: Qualcomm Atheros Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33} ©
O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App © =>.WildTangent
O42 - Logiciel: ASUS Smart Gesture - (.ASUS.) [HKLM][64Bits] -- {4D3286A6-F6AB-498A-82A4-E4F040529F3D} ©
O42 - Logiciel: Grand Theft Auto IV - (.Rockstar Games.) [HKLM][64Bits] -- {579BA58C-F33D-4970-9953-B94B43768AC3} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} ©
O42 - Logiciel: WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-asus © =>.WildTangent
O42 - Logiciel: ASUS InstantOn - (.ASUS.) [HKLM][64Bits] -- {749F674B-2674-47E8-879C-5626A06B2A91} ©
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} ©
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} ©
O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} ©
O42 - Logiciel: WinFlash - (.ASUS.) [HKLM][64Bits] -- {8F21291E-0444-4B1D-B9F9-4370A73E346D} ©
O42 - Logiciel: Galería de fotos - (.Microsoft Corporation.) [HKLM][64Bits] -- {8F7FECEC-088F-431D-A5FB-2B59E1E69943} ©
O42 - Logiciel: ASUS USB Charger Plus - (.ASUS.) [HKLM][64Bits] -- {A859E3E5-C62F-4BFA-AF1D-2B95E03166AF} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ©
O42 - Logiciel: ATK Package - (.ASUS.) [HKLM][64Bits] -- {AB5C933E-5C7D-4D30-B314-9C83A49B94BE} ©
O42 - Logiciel: Adobe Reader X MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001} ©
O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {C1594429-8296-4652-BF54-9DBE4932A44C} ©
O42 - Logiciel: aTube Catcher versão 3.8 - (.DsNET Corp.) [HKLM][64Bits] -- {D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1 ©
O42 - Logiciel: ASUSDVD - (.CyberLink Corp..) [HKLM][64Bits] -- {DEC235ED-58A4-4517-A278-C41E8DAEAB3B} ©
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} ©
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} ©
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} ©
O42 - Logiciel: Galeria de Fotos - (.Microsoft Corporation.) [HKLM][64Bits] -- {F5248B7E-779A-4FA4-8134-D1933D8680FA} ©
O42 - Logiciel: Galeria de Fotografias - (.Microsoft Corporation.) [HKLM][64Bits] -- {F5E338CE-E1C6-4F7D-8300-44DBD05B9F14} ©
O42 - Logiciel: ASUS Live Update - (.ASUS.) [HKLM][64Bits] -- {FA540E67-095C-4A1B-97BA-4D547DEC9AF4} ©
O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573} ©
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe ©

---\\ HKCU & HKLM Software Keys (148) - 9s
HKLM\SOFTWARE\Wow6432Node\4HD
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AdwCleaner
HKLM\SOFTWARE\Wow6432Node\AppDataLow
HKLM\SOFTWARE\Wow6432Node\ASIO
HKLM\SOFTWARE\Wow6432Node\AsLdr
HKLM\SOFTWARE\Wow6432Node\ASUS
HKLM\SOFTWARE\Wow6432Node\Atheros
HKLM\SOFTWARE\Wow6432Node\baidu
HKLM\SOFTWARE\Wow6432Node\Baidu Security
HKLM\SOFTWARE\Wow6432Node\Baidu_Drp_pos
HKLM\SOFTWARE\Wow6432Node\Client
HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse
HKLM\SOFTWARE\Wow6432Node\CyberLink
HKLM\SOFTWARE\Wow6432Node\Disc Soft
HKLM\SOFTWARE\Wow6432Node\ECAREME
HKLM\SOFTWARE\Wow6432Node\EVP
HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP =>PUP.Optional.GamesDesktop
HKLM\SOFTWARE\Wow6432Node\GameVicio
HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKLM\SOFTWARE\Wow6432Node\InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\istartsurfSoftware =>PUP.Optional.IsStart
HKLM\SOFTWARE\Wow6432Node\iWebar-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\iWebar-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\Lake
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\MaxPower
HKLM\SOFTWARE\Wow6432Node\McAfee
HKLM\SOFTWARE\Wow6432Node\MediaBuzzV1 =>PUP.Optional.MediaBuzz
HKLM\SOFTWARE\Wow6432Node\MediaBuzzV1mode9081 =>PUP.Optional.MediaBuzz
HKLM\SOFTWARE\Wow6432Node\MediaPlayerVideos 1.2 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Mooii
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mystarttb =>PUP.Optional.StartSearch
HKLM\SOFTWARE\Wow6432Node\NetTcpHandler
HKLM\SOFTWARE\Wow6432Node\NtSvcHandler
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\Object Browser-nv =>PUP.Optional.ObjectBrowser
HKLM\SOFTWARE\Wow6432Node\Object Browser-nv-ie =>PUP.Optional.ObjectBrowser
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\PowerPivot
HKLM\SOFTWARE\Wow6432Node\Primary Color =>PUP.Optional.PrimaryColor
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\Realtek
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Rockstar Games
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\Sm23mS-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Sm23mS-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ss8-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ss8-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SuppHelpDir
HKLM\SOFTWARE\Wow6432Node\TrustMediaViewerV1
HKLM\SOFTWARE\Wow6432Node\TrustMediaViewerV1alpha4099
HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive
HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue
HKLM\SOFTWARE\Wow6432Node\Valve
HKLM\SOFTWARE\Wow6432Node\VideoLAN
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro
HKLM\SOFTWARE\Wow6432Node\WildTangent
HKLM\SOFTWARE\Wow6432Node\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\7bYlFUrYPA44zgjE
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ARAR
HKCU\SOFTWARE\ASUS
HKCU\SOFTWARE\Audacity
HKCU\SOFTWARE\Baidu
HKCU\SOFTWARE\Baidu Security
HKCU\SOFTWARE\Baixaki
HKCU\SOFTWARE\BrowserApp2.1 =>PUP.Optional.CrossRider
HKCU\SOFTWARE\BrowserApp2.1-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\BrowserApp2.1-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\CinemaPlus-3.2cV06.09 =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV06.09-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV06.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ClkApp
HKCU\SOFTWARE\Crossbrowse =>PUP.Optional.CrossBrowse
HKCU\SOFTWARE\CrossBrowser =>PUP.Optional.CrossBrowser
HKCU\SOFTWARE\CyberLink
HKCU\SOFTWARE\Disc Soft
HKCU\SOFTWARE\Easy Speed Check
HKCU\SOFTWARE\ECAREME
HKCU\SOFTWARE\Facebook
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKCU\SOFTWARE\InstallPath
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\iWebar-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\kde.org
HKCU\SOFTWARE\Lake
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\MGinstall
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mooii
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\Object Browser-nv =>PUP.Optional.ObjectBrowser
HKCU\SOFTWARE\Object Browser-nv-ie =>PUP.Optional.ObjectBrowser
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\PopWnd
HKCU\SOFTWARE\Primary Color =>PUP.Optional.PrimaryColor
HKCU\SOFTWARE\Pritc
HKCU\SOFTWARE\Probit Software =>PUP.Optional.ProbitSoftware
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\SecuROM
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\SkypeRS
HKCU\SOFTWARE\Sm23mS-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Sm23mS-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ss8-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ss8-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\The Silicon Realms Toolworks
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\tstamptoken =>PUP.Optional.MaxComputerCleaner
HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\U4ivfRNw7Uj6k
HKCU\SOFTWARE\Valve
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\VLCU
HKCU\SOFTWARE\VSRevoGroup
HKCU\SOFTWARE\WebApp
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\YeaInstaller
HKCU\SOFTWARE\Yeaplayer
HKCU\SOFTWARE\yI9zJl7XcMs
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider

---\\ Conteúdo das pastas Programs (173) - 8s
O43 - CFD: 2013/04/25 19:39:28 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2014/07/02 21:43:44 - [] D -- C:\Program Files (x86)\ARAR
O43 - CFD: 2013/10/26 22:22:11 - [] D -- C:\Program Files (x86)\ASUS
O43 - CFD: 2015/09/10 13:28:37 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2013/12/18 13:12:02 - [] D -- C:\Program Files (x86)\Counter-Strike 1.6
O43 - CFD: 2013/10/26 22:19:41 - [] D -- C:\Program Files (x86)\CyberLink
O43 - CFD: 2014/01/09 10:40:17 - [] D -- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 2015/04/03 19:11:29 - [] D -- C:\Program Files (x86)\DsNET Corp
O43 - CFD: 2015/04/05 21:57:46 - [] D -- C:\Program Files (x86)\GameVicio
O43 - CFD: 2015/09/10 14:11:48 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2015/08/28 21:35:26 - [] D -- C:\Program Files (x86)\IHMC CmapTools
O43 - CFD: 2015/04/19 09:55:45 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 2013/10/26 22:09:15 - [] D -- C:\Program Files (x86)\Intel
O43 - CFD: 2015/05/18 18:21:39 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2014/10/14 08:45:50 - [] D -- C:\Program Files (x86)\KONAMI
O43 - CFD: 2015/06/23 18:15:23 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2014/12/13 10:55:37 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2015/08/19 18:47:24 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 2013/04/25 19:40:42 - [] D -- C:\Program Files (x86)\Microsoft SkyDrive
O43 - CFD: 2015/06/23 18:21:01 - [] D -- C:\Program Files (x86)\Microsoft SQL Server
O43 - CFD: 2014/12/13 10:55:37 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 2015/06/23 18:21:00 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2014/01/04 12:13:27 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2015/03/18 18:19:38 - [] D -- C:\Program Files (x86)\PhotoScape
O43 - CFD: 2015/09/13 20:46:35 - [] D -- C:\Program Files (x86)\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic
O43 - CFD: 2013/10/26 22:03:11 - [] D -- C:\Program Files (x86)\Qualcomm Atheros
O43 - CFD: 2013/10/26 22:14:00 - [] D -- C:\Program Files (x86)\Realtek
O43 - CFD: 2014/01/04 12:13:27 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/04/19 09:55:46 - [] D -- C:\Program Files (x86)\Rockstar Games
O43 - CFD: 2015/09/03 21:45:46 - [] RD -- C:\Program Files (x86)\Skype
O43 - CFD: 2013/10/26 22:12:02 - [0] HD -- C:\Program Files (x86)\Temp
O43 - CFD: 2015/01/11 14:19:11 - [] D -- C:\Program Files (x86)\Valve
O43 - CFD: 2015/01/14 19:15:45 - [] D -- C:\Program Files (x86)\VideoLAN
O43 - CFD: 2015/09/06 21:06:23 - [] D -- C:\Program Files (x86)\VS Revo Group
O43 - CFD: 2013/04/25 19:44:49 - [] D -- C:\Program Files (x86)\WildGames
O43 - CFD: 2013/04/25 19:44:11 - [] D -- C:\Program Files (x86)\WildTangent Games
O43 - CFD: 2015/04/20 16:39:04 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2013/04/25 19:41:31 - [] D -- C:\Program Files (x86)\Windows Live
O43 - CFD: 2014/12/13 14:12:04 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2014/12/13 14:11:58 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2014/12/13 14:12:04 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 2013/08/22 12:36:30 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2014/12/13 14:11:57 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2014/12/13 14:11:59 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2014/01/04 11:32:44 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2013/08/22 12:36:30 - [] D -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 2015/09/10 14:14:59 - [] D -- C:\Program Files (x86)\Yeaplayer
O43 - CFD: 2015/08/28 21:35:27 - [] HD -- C:\Program Files (x86)\Zero G Registry
O43 - CFD: 2014/12/13 14:16:52 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/04/20 16:39:05 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2014/12/13 14:16:52 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/07/02 21:43:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced RAR Repair
O43 - CFD: 2015/09/08 10:52:28 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
O43 - CFD: 2014/01/04 11:32:46 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUSDVD
O43 - CFD: 2015/04/03 19:11:45 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
O43 - CFD: 2014/01/09 10:40:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
O43 - CFD: 2014/01/04 11:34:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2015/04/05 21:57:46 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameVicio
O43 - CFD: 2015/09/10 16:15:32 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2014/02/16 20:50:29 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hao123-Brazil
O43 - CFD: 2015/08/28 21:35:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IHMC CmapTools
O43 - CFD: 2014/01/04 11:34:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
O43 - CFD: 2013/08/22 12:36:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/06/23 18:23:24 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
O43 - CFD: 2015/08/16 10:34:11 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2014/04/21 14:54:48 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
O43 - CFD: 2015/04/19 09:55:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
O43 - CFD: 2015/09/03 21:45:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 2015/09/08 20:53:28 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2014/12/13 14:16:52 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2013/11/14 04:15:44 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2014/01/04 11:34:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/09/10 14:15:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yeaplayer
O43 - CFD: 2015/01/23 08:47:14 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2014/06/23 19:06:17 - [] D -- C:\ProgramData\AnyAppSnow
O43 - CFD: 2013/08/22 11:45:52 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/09/12 18:10:45 - [] D -- C:\ProgramData\AppMgr3.57.4713165 =>PUP.Optional.Generic
O43 - CFD: 2014/01/22 18:14:59 - [] D -- C:\ProgramData\ASUS
O43 - CFD: 2013/04/25 19:40:22 - [] D -- C:\ProgramData\ASUS WebStorage
O43 - CFD: 2013/04/25 19:39:23 - [] D -- C:\ProgramData\ASUSLogos
O43 - CFD: 2013/10/26 22:22:14 - [] D -- C:\ProgramData\ASUSVibe
O43 - CFD: 2014/01/09 13:37:23 - [] D -- C:\ProgramData\baidu
O43 - CFD: 2015/01/17 12:09:17 - [] D -- C:\ProgramData\Baidu Security
O43 - CFD: 2013/12/03 21:16:03 - [] D -- C:\ProgramData\CyberLink
O43 - CFD: 2014/01/04 11:44:48 - [0] SHD -- C:\ProgramData\Dados de Aplicativos
O43 - CFD: 2014/01/09 11:12:45 - [] D -- C:\ProgramData\DAEMON Tools Lite
O43 - CFD: 2013/08/22 11:45:52 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2014/01/04 11:44:48 - [0] SHD -- C:\ProgramData\Documentos
O43 - CFD: 2013/08/22 11:45:52 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2013/10/26 22:08:13 - [] D -- C:\ProgramData\Intel
O43 - CFD: 2014/12/16 21:59:18 - [] D -- C:\ProgramData\KONAMI
O43 - CFD: 2014/01/09 14:07:52 - [] D -- C:\ProgramData\Log
O43 - CFD: 2014/01/09 11:46:45 - [] D -- C:\ProgramData\Logs
O43 - CFD: 2015/05/15 19:42:07 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 2013/12/20 16:59:00 - [] D -- C:\ProgramData\McAfee
O43 - CFD: 2014/01/04 11:44:48 - [0] SHD -- C:\ProgramData\Menu Iniciar
O43 - CFD: 2014/12/13 14:16:54 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/06/23 18:24:35 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2014/02/20 17:40:33 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 2013/04/25 19:40:42 - [] D -- C:\ProgramData\Microsoft SkyDrive
O43 - CFD: 2015/06/23 19:03:27 - [] D -- C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
O43 - CFD: 2014/01/04 11:44:48 - [0] SHD -- C:\ProgramData\Modelos
O43 - CFD: 2015/09/08 11:21:14 - [] D -- C:\ProgramData\Ovafunaveh
O43 - CFD: 2013/10/26 22:19:23 - [] D -- C:\ProgramData\P4G
O43 - CFD: 2014/01/04 11:32:48 - [] D -- C:\ProgramData\PRICache
O43 - CFD: 2013/10/26 22:03:03 - [] D -- C:\ProgramData\Qualcomm Atheros
O43 - CFD: 2015/06/23 18:20:21 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/09/03 21:45:50 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2013/08/22 11:45:52 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2014/12/15 19:27:52 - [] D -- C:\ProgramData\Steam
O43 - CFD: 2014/01/09 11:46:45 - [] D -- C:\ProgramData\Temp
O43 - CFD: 2013/08/22 11:45:52 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2013/10/26 22:29:26 - [] D -- C:\ProgramData\USBChargerPlus
O43 - CFD: 2013/04/25 19:44:15 - [] D -- C:\ProgramData\WildTangent
O43 - CFD: 2015/09/10 13:28:36 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2015/09/10 13:28:37 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 2015/09/10 13:28:37 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2013/04/25 19:40:33 - [] D -- C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 2014/01/09 17:25:52 - [] D -- C:\Users\Teco\AppData\Roaming\Adobe
O43 - CFD: 2013/12/03 16:10:59 - [] D -- C:\Users\Teco\AppData\Roaming\ASUS WebStorage
O43 - CFD: 2015/08/25 13:15:35 - [] D -- C:\Users\Teco\AppData\Roaming\Audacity
O43 - CFD: 2014/02/16 20:53:28 - [] D -- C:\Users\Teco\AppData\Roaming\Baidu
O43 - CFD: 2015/08/30 11:59:46 - [] D -- C:\Users\Teco\AppData\Roaming\CmapTools
O43 - CFD: 2013/12/03 21:15:58 - [] D -- C:\Users\Teco\AppData\Roaming\CyberLink
O43 - CFD: 2015/04/02 08:08:47 - [] D -- C:\Users\Teco\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 2015/09/07 11:16:27 - [] D -- C:\Users\Teco\AppData\Roaming\DNSHelper
O43 - CFD: 2015/09/01 22:14:55 - [] D -- C:\Users\Teco\AppData\Roaming\dvdcss
O43 - CFD: 2014/01/04 11:47:52 - [] D -- C:\Users\Teco\AppData\Roaming\Identities
O43 - CFD: 2013/12/03 16:14:14 - [] D -- C:\Users\Teco\AppData\Roaming\Macromedia
O43 - CFD: 2015/07/31 12:55:58 - [] SD -- C:\Users\Teco\AppData\Roaming\Microsoft
O43 - CFD: 2015/08/28 21:18:47 - [] D -- C:\Users\Teco\AppData\Roaming\NetService
O43 - CFD: 2015/03/19 19:34:49 - [] D -- C:\Users\Teco\AppData\Roaming\PhotoScape
O43 - CFD: 2015/09/07 11:16:23 - [] D -- C:\Users\Teco\AppData\Roaming\RunDir
O43 - CFD: 2015/09/09 20:07:20 - [] D -- C:\Users\Teco\AppData\Roaming\ScreenSnapshotTool
O43 - CFD: 2015/09/03 21:46:10 - [] D -- C:\Users\Teco\AppData\Roaming\Skype
O43 - CFD: 2015/09/06 15:39:07 - [] D -- C:\Users\Teco\AppData\Roaming\vlc
O43 - CFD: 2013/12/05 20:43:41 - [] D -- C:\Users\Teco\AppData\Roaming\WildTangent
O43 - CFD: 2013/12/04 10:31:58 - [] D -- C:\Users\Teco\AppData\Roaming\WinRAR
O43 - CFD: 2015/09/14 18:40:10 - [] D -- C:\Users\Teco\AppData\Roaming\ZHP
O43 - CFD: 2015/01/17 11:51:54 - [] D -- C:\Users\Teco\AppData\Local\Adobe
O43 - CFD: 2014/01/08 16:31:39 - [] D -- C:\Users\Teco\AppData\Local\ApplicationHistory
O43 - CFD: 2013/12/05 21:14:32 - [] D -- C:\Users\Teco\AppData\Local\Apps
O43 - CFD: 2013/12/03 16:11:20 - [] D -- C:\Users\Teco\AppData\Local\ASUS
O43 - CFD: 2015/09/14 14:42:19 - [0] D -- C:\Users\Teco\AppData\Local\Comodo
O43 - CFD: 2014/12/24 15:32:11 - [] D -- C:\Users\Teco\AppData\Local\Cyberlink
O43 - CFD: 2014/01/04 11:28:20 - [0] SHD -- C:\Users\Teco\AppData\Local\Dados de Aplicativos
O43 - CFD: 2015/08/25 13:16:45 - [0] D -- C:\Users\Teco\AppData\Local\Deployment
O43 - CFD: 2015/08/25 18:57:30 - [] D -- C:\Users\Teco\AppData\Local\Diagnostics
O43 - CFD: 2015/09/07 11:36:33 - [] D -- C:\Users\Teco\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2015/01/09 15:58:10 - [] SHD -- C:\Users\Teco\AppData\Local\EmieBrowserModeList
O43 - CFD: 2014/05/29 12:50:56 - [] SHD -- C:\Users\Teco\AppData\Local\EmieSiteList
O43 - CFD: 2014/05/29 12:50:56 - [] SHD -- C:\Users\Teco\AppData\Local\EmieUserList
O43 - CFD: 2015/09/09 20:47:37 - [] D -- C:\Users\Teco\AppData\Local\F7307D8A-7D6-400F-AB1D-5A999A51556
O43 - CFD: 2013/12/18 12:39:30 - [] D -- C:\Users\Teco\AppData\Local\Facebook
O43 - CFD: 2014/04/18 16:26:37 - [] D -- C:\Users\Teco\AppData\Local\FreeZipViewer
O43 - CFD: 2015/09/14 14:42:19 - [] D -- C:\Users\Teco\AppData\Local\Google
O43 - CFD: 2015/06/02 20:39:14 - [] D -- C:\Users\Teco\AppData\Local\GWX
O43 - CFD: 2014/01/04 11:28:20 - [0] SHD -- C:\Users\Teco\AppData\Local\Histórico
O43 - CFD: 2015/09/08 10:08:05 - [] D -- C:\Users\Teco\AppData\Local\macasoft
O43 - CFD: 2015/07/12 22:43:00 - [] D -- C:\Users\Teco\AppData\Local\Microsoft
O43 - CFD: 2015/04/11 14:49:54 - [] D -- C:\Users\Teco\AppData\Local\Microsoft Help
O43 - CFD: 2015/09/12 12:59:47 - [] D -- C:\Users\Teco\AppData\Local\Packages
O43 - CFD: 2014/01/09 11:46:25 - [] D -- C:\Users\Teco\AppData\Local\Programs
O43 - CFD: 2015/04/18 18:20:39 - [] D -- C:\Users\Teco\AppData\Local\Rockstar Games
O43 - CFD: 2014/01/31 16:43:43 - [] D -- C:\Users\Teco\AppData\Local\Skype
O43 - CFD: 2015/09/14 18:39:50 - [] D -- C:\Users\Teco\AppData\Local\Temp
O43 - CFD: 2014/01/04 11:28:20 - [0] SHD -- C:\Users\Teco\AppData\Local\Temporary Internet Files
O43 - CFD: 2014/01/31 16:18:58 - [] D -- C:\Users\Teco\AppData\Local\VirtualStore
O43 - CFD: 2015/09/08 11:00:42 - [] D -- C:\Users\Teco\AppData\Local\VLCUpdate
O43 - CFD: 2014/12/16 22:04:36 - [] D -- C:\Users\Teco\AppData\Local\Windows Live
O43 - CFD: 2015/09/10 14:17:24 - [] D -- C:\Users\Teco\AppData\Local\Yeaplayer
O43 - CFD: 2015/09/11 12:56:35 - [] RD -- C:\Users\Teco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/09/11 13:16:27 - [] RD -- C:\Users\Teco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

---\\ Últimos arquivos criados no Windows Prefetcher (2) - 9s
O45 - LFCP:[MD5.D50A11D8100409796675EA1167FEA401] 2015/09/08 10:16:06 A -- C:\WINDOWS\Prefetch\ANYPROTECT.EXE-53752276.pf =>PUP.Optional.AnyProtect
O45 - LFCP:[MD5.3BB3ED10D78C7EE12A52B4FA8D7847B5] 2015/09/10 13:21:18 A -- C:\WINDOWS\Prefetch\OLBPRE.EXE-5FD45ACB.pf =>PUP.Optional.MyPCBackup

---\\ Enumeração das chaves StartupReg (7) - 1s
O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe ©
O53 - SMSR:HKLM\...\startupreg\ASUSPRP [Key] . (.ASUSTek Computer Inc. - ASUS Product Register Program.) -- C:\Program Files (x86)\ASUS\APRP\aprp.exe ©
O53 - SMSR:HKLM\...\startupreg\ASUSWebStorage [Key] . (.ASUS Cloud Corporation - ASUS WebStorage Panel.) -- C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe ©
O53 - SMSR:HKLM\...\startupreg\DisableS3S4 [Key] . (...) -- c:\windows\temp\DisableS3S464\sethigh.cmd (.not file.)
O53 - SMSR:HKLM\...\startupreg\RemoteControl10 [Key] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe ©
O53 - SMSR:HKLM\...\startupreg\RtHDVBg [Key] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe ©
O53 - SMSR:HKLM\...\startupreg\RTHDVCPL [Key] . (.Realtek Semiconductor - Gerenciador de áudio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ©

---\\ Lista dos drivers do sistema (52) - 9s
O58 - SDL:2013/08/22 09:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [108896] ©
O58 - SDL:2013/08/22 09:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [782176] ©
O58 - SDL:2012/09/18 16:51:54 A . (.ASUSTek Computer Inc. - ASUS Charger driver.) -- C:\WINDOWS\System32\drivers\AiCharger.sys [17152] ©
O58 - SDL:2013/08/22 09:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [79200] ©
O58 - SDL:2013/08/22 09:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] ©
O58 - SDL:2013/08/22 09:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [25952] ©
O58 - SDL:2013/08/22 09:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [114016] ©
O58 - SDL:2013/11/04 03:32:06 A . (.ASUS - HID driver for ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [20280] ©
O58 - SDL:2013/04/16 21:25:46 A . (.ASUS Corporation - Asus TP Filter Driver.) -- C:\WINDOWS\System32\drivers\AsusTP.sys [65784] ©
O58 - SDL:2013/06/18 11:45:02 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athw8x.sys [3680256] ©
O58 - SDL:2013/08/14 03:42:44 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athwbx.sys [3837440] ©
O58 - SDL:2013/08/12 20:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] ©
O58 - SDL:2013/12/17 06:59:26 A . (.Baidu, Inc. - Baidu Antivirus Minifilter Driver.) -- C:\WINDOWS\System32\drivers\Bfilter.sys [52032] ©
O58 - SDL:2013/12/17 06:59:30 A . (.Baidu, Inc. - Baidu FS Monitor Driver.) -- C:\WINDOWS\System32\drivers\Bfmon.sys [34624] ©
O58 - SDL:2013/12/18 06:11:04 A . (.Baidu, Inc. - Baidu Antivirus Selfprotect Driver.) -- C:\WINDOWS\System32\drivers\Bprotect.sys [128448] ©
O58 - SDL:2013/08/22 09:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] ©
O58 - SDL:2014/01/09 10:40:17 A . (.Disc Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283064] ©
O58 - SDL:2013/08/22 09:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3357024] ©
O58 - SDL:2012/07/02 19:16:02 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [62784] ©
O58 - SDL:2013/08/22 09:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] ©
O58 - SDL:2013/07/30 15:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [24568] ©
O58 - SDL:2013/07/25 16:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [99320] ©
O58 - SDL:2012/09/14 02:15:10 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [647736] ©
O58 - SDL:2013/08/09 21:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [651248] ©
O58 - SDL:2013/08/22 09:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] ©
O58 - SDL:2012/12/13 19:14:20 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [5353888] ©
O58 - SDL:2013/01/08 23:26:24 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [342528] ©
O58 - SDL:2012/08/02 00:22:48 A . (. - Keyboard Filter Driver.) -- C:\WINDOWS\System32\drivers\kbfiltr.sys [14992]
O58 - SDL:2013/08/22 09:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [109408] ©
O58 - SDL:2013/08/22 09:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2.sys [93536] ©
O58 - SDL:2013/08/22 09:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3.sys [81760] ©
O58 - SDL:2013/08/22 09:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] ©
O58 - SDL:2013/08/22 09:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [56672] ©
O58 - SDL:2013/08/22 09:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] ©
O58 - SDL:2015/01/19 11:06:14 A . (.Windows (R) Win 7 DDK provider - NetFilter SDK WFP Driver (WPP).) -- C:\WINDOWS\System32\drivers\mosfilterdrv.sys [64824] ©
O58 - SDL:2013/08/22 09:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] ©
O58 - SDL:2013/08/22 09:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] ©
O58 - SDL:2013/08/22 09:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [168288] ©
O58 - SDL:2014/12/02 17:57:10 A . (.Windows (R) Win 7 DDK provider - NetFilter SDK WFP Driver (WPP).) -- C:\WINDOWS\System32\drivers\pofilterdrv.sys [53568] ©
O58 - SDL:2013/11/29 03:32:14 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\WINDOWS\System32\drivers\Rt630x64.sys [838872] ©
O58 - SDL:2013/06/04 10:36:08 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [3441992] ©
O58 - SDL:2015/06/04 09:23:02 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\WINDOWS\System32\drivers\RtsBaStor.sys [321792] ©
O58 - SDL:2013/08/22 12:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [23040] ©
O58 - SDL:2013/08/22 09:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] ©
O58 - SDL:2013/08/22 09:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] ©
O58 - SDL:2014/01/22 07:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [108800] ©
O58 - SDL:2014/01/22 07:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [206080] ©
O58 - SDL:2013/08/22 09:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] ©
O58 - SDL:2013/08/22 09:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\WINDOWS\System32\drivers\viaide.sys [19808] ©
O58 - SDL:2013/08/22 09:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [168800] ©
O58 - SDL:2013/08/22 09:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] ©
O58 - SDL:2012/11/19 03:57:58 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athw8x.sys [3728384] ©

---\\ Últimos ficheiros alterados ou criados (Utilizador) (20) - 61s
O61 - LFC: 2015/09/11 18:25:52 A . (..) -- C:\Users\Teco\Downloads\zoek.exe [1308672]
O61 - LFC: 2015/09/12 14:45:04 A . (..) -- C:\Users\Teco\Documents\KONAMI\Pro Evolution Soccer 2015\save\ML 01.bin [14951861]
O61 - LFC: 2015/09/12 15:15:50 A . (..) -- C:\Users\Teco\Documents\KONAMI\Pro Evolution Soccer 2015\save\ML 04.bin [14951852]
O61 - LFC: 2015/09/13 14:35:58 A . (..) -- C:\Users\Teco\Documents\KONAMI\Pro Evolution Soccer 2015\save\SYSTEM.bin [136577]
O61 - LFC: 2015/09/07 08:06:25 A . (..) -- C:\Users\Teco\AppData\Roaming\RunDir\srp.exe [142792]
O61 - LFC: 2015/09/07 08:06:25 A . (..) -- C:\Users\Teco\AppData\Roaming\RunDir\temp\srp.exe [142792]
O61 - LFC: 2015/09/07 08:06:25 A . (..) -- C:\Users\Teco\AppData\Roaming\DNSHelper\DNSSVC.exe [142792]
O61 - LFC: 2015/09/13 15:00:16 A . (..) -- C:\Users\Teco\AppData\Local\Packages\GAMELOFTSA.Asphalt8Airborne_0pp20fcewvvtj\LocalState\gv3\Batched.bin [1500]
O61 - LFC: 2015/09/13 15:00:16 A . (..) -- C:\Users\Teco\AppData\Local\Packages\GAMELOFTSA.Asphalt8Airborne_0pp20fcewvvtj\LocalState\gv3\Priority.bin [1472]
O61 - LFC: 2015/09/13 14:59:13 A . (..) -- C:\Users\Teco\AppData\Local\Packages\GAMELOFTSA.Asphalt8Airborne_0pp20fcewvvtj\LocalState\gv3\Sessions.bin [111]
O61 - LFC: 2015/09/13 15:00:16 A . (..) -- C:\Users\Teco\AppData\Local\Packages\GAMELOFTSA.Asphalt8Airborne_0pp20fcewvvtj\LocalState\gv3\Stream.bin [3602]
O61 - LFC: 2015/09/13 15:00:13 A . (..) -- C:\Users\Teco\AppData\Local\Packages\GAMELOFTSA.Asphalt8Airborne_0pp20fcewvvtj\LocalState\gv3\Timer.bin [156]
O61 - LFC: 2015/09/13 15:00:08 A . (..) -- C:\Users\Teco\AppData\Local\Packages\GAMELOFTSA.Asphalt8Airborne_0pp20fcewvvtj\LocalState\gv3\Token.bin [113]
O61 - LFC: 2015/09/11 20:14:14 A . (.Copyright © 2012.) -- C:\Users\Teco\AppData\Local\Packages\39976Virblue.MyStudyLife_pa3njxwv09jym\AC\Microsoft\CLR_v4.0\NativeImages\MyStudyLife313228e7#\cab52e545ff05d2a8b17d5d9af50e3da\MyStudyLife.W8.BackgroundTasks.ni.dll [47104]
O61 - LFC: 2015/09/11 20:14:32 A . (.Copyright © 2012.) -- C:\Users\Teco\AppData\Local\Packages\39976Virblue.MyStudyLife_pa3njxwv09jym\AC\Microsoft\CLR_v4.0\NativeImages\MyStudyLife.W8.Core\f51c8401c3f79f284e701d101b41cf66\MyStudyLife.W8.Core.ni.dll [221696]
O61 - LFC: 2015/09/11 20:14:53 A . (.Copyright © 2012.) -- C:\Users\Teco\AppData\Local\Packages\39976Virblue.MyStudyLife_pa3njxwv09jym\AC\Microsoft\CLR_v4.0\NativeImages\MyStudyLife.Core\d816e8d3797af5491fe5dfc0404edb9f\MyStudyLife.Core.ni.dll [2613760]
O61 - LFC: 2015/09/08 02:45:44 A . (..) -- C:\Users\Teco\AppData\Local\macasoft\ntsvc.exe [121728]
O61 - LFC: 2015/09/14 15:16:19 A . (..) -- C:\Users\Teco\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [674082]
O61 - LFC: 2015/09/14 18:38:55 A . (..) -- C:\Users\Teco\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [200]
O61 - LFC: 2015/09/09 20:47:24 A . (..) -- C:\Users\Teco\AppData\Local\F7307D8A-7D6-400F-AB1D-5A999A51556\F7307D8A-7D6-400F-AB1D-5A999A51556.exe [1998408]

---\\ Associações Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de inicialização Internet (8) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe ©

---\\ Pesquisa de infeção nos navegadores da Internet (2) - 0s
O69 - SBI: SearchScopes [HKCU] {012E1000-F331-11DB-8314-0800200C9A66} - (Google) - http://www.google.com/
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/

---\\ Listagem dos serviços iniciados pelo Svchost (34) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Serviço de Experiência com Aplicativo.) -- C:\WINDOWS\System32\aelupsvc.dll [214528] ©
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\WINDOWS\System32\certprop.dll [156160] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\WINDOWS\System32\certprop.dll [156160] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\WINDOWS\system32\srvsvc.dll [329216] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\WINDOWS\System32\gpsvc.dll [1360896] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\WINDOWS\System32\ikeext.dll [1084416] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\WINDOWS\System32\iphlpsvc.dll [926208] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\WINDOWS\system32\seclogon.dll [31744] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\WINDOWS\System32\appinfo.dll [110080] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\WINDOWS\System32\eapsvc.dll [110592] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\WINDOWS\system32\schedsvc.dll [1265152] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [230400] ©
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Serviço Agendador de Classes de Multimídia.) -- C:\WINDOWS\system32\mmcss.dll [71168] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\WINDOWS\System32\browser.dll [135168] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [225280] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho.) -- C:\Windows\System32\SessEnv.dll [339968] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\WINDOWS\System32\wercplsupport.dll [84992] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\WINDOWS\system32\kmsvc.dll [101376] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\WINDOWS\System32\bdesvc.dll [348672] ©
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Serviço de Estrutura de Localização do Wind.) -- C:\Windows\System32\GeofenceMonitorService.dll [521728] ©
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [1639424] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\WINDOWS\system32\themeservice.dll [59392] ©
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [206848] ©
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede.) -- C:\WINDOWS\System32\ncasvc.dll [166400] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acess.) -- C:\WINDOWS\System32\rasauto.dll [102912] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\WINDOWS\System32\rasmans.dll [542208] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [226816] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) -- C:\WINDOWS\System32\sens.dll [73728] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\WINDOWS\System32\ipnathlp.dll [452608] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft(R) Windo.) -- C:\Windows\System32\tapisrv.dll [313344] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\system32\wuaueng.dll [3678720] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) -- C:\WINDOWS\System32\qmgr.dll [933376] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [640000] ©

---\\ Lista das exceções do FireWall (FirewallRules) (38) - 3s
O87 - FAEL: "{6D2AB80A-0B55-4BA8-A021-A49E37CB1EB5}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\WinZip Driver Updater\winzipdu.exe (.not file.)
O87 - FAEL: "{FCC4076A-81D0-435E-8948-2337F84F2E74}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (.not file.)
O87 - FAEL: "{EA234094-B17E-4BF2-8403-76EF9348921A}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (.not file.)
O87 - FAEL: "{F982B908-EF5A-4673-B12D-693C50D63A56}" [In-None-P6-TRUE] .(...) -- C:\Users\Teco\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (.not file.)
O87 - FAEL: "{E1B8C928-5887-4304-829E-9CE6F451D95E}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (.not file.)
O87 - FAEL: "{02090F1A-D9B7-4905-8A47-552BBCB8763D}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (.not file.)
O87 - FAEL: "TCP Query User{4FA5EEBD-91CC-4D87-8575-51A53E1D8618}C:\users\teco\desktop\utorrent-1-.exe" [In-None-P6-TRUE] .(...) -- C:\users\teco\desktop\utorrent-1-.exe (.not file.)
O87 - FAEL: "UDP Query User{F6B64AE5-7963-40A8-BD5D-9F6D248F1050}C:\users\teco\desktop\utorrent-1-.exe" [In-None-P17-TRUE] .(...) -- C:\users\teco\desktop\utorrent-1-.exe (.not file.)
O87 - FAEL: "{A9941687-EF23-46F5-B7F9-485B7D6C44F1}" [Out-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe (.not file.) =>PUP.Optional.DllFilesFixer
O87 - FAEL: "{17EB233F-A144-4905-A929-BA62864F6154}" [Out-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe (.not file.) =>PUP.Optional.DllFilesFixer
O87 - FAEL: "{4FABB5F2-DEF6-48C0-A9E6-043929C12F35}" [Out-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe (.not file.) =>PUP.Optional.DllFilesFixer
O87 - FAEL: "{BF3D2BD1-F0B9-4DD7-B511-F948811D39C5}" [Out-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe (.not file.) =>PUP.Optional.DllFilesFixer
O87 - FAEL: "TCP Query User{A785E21F-7C1E-464F-ACFD-CB36CBB34BDE}C:\users\teco\desktop\utorrent-1-.exe" [In-None-P6-TRUE] .(...) -- C:\users\teco\desktop\utorrent-1-.exe (.not file.)
O87 - FAEL: "UDP Query User{F37D5A73-531B-4825-BDEE-41E36B66069D}C:\users\teco\desktop\utorrent-1-.exe" [In-None-P17-TRUE] .(...) -- C:\users\teco\desktop\utorrent-1-.exe (.not file.)
O87 - FAEL: "TCP Query User{F2E045A7-75CB-449A-BB0E-8D8ED490C4C5}C:\program files (x86)\konami\pro evolution soccer 2009\pes2009.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\konami\pro evolution soccer 2009\pes2009.exe (.not file.)
O87 - FAEL: "UDP Query User{4E31FE40-E7B6-4FA5-9941-01EA3ED03971}C:\program files (x86)\konami\pro evolution soccer 2009\pes2009.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\konami\pro evolution soccer 2009\pes2009.exe (.not file.)
O87 - FAEL: "{2893A4AB-7A77-47DA-A9C6-C0866E9DAD9C}" [In-None-P6-TRUE] .(...) -- C:\Users\Teco\AppData\Local\Beamrise\Application\31.0.1650.7639\services\windows-x86-skypekit.exe (.not file.) =>PUP.Optional.Beamrise
O87 - FAEL: "{E0E1C089-8FDE-44C6-B1EB-AEA193B97F02}" [Out-None-P6-TRUE] .(...) -- C:\Users\Teco\AppData\Local\Beamrise\Application\31.0.1650.7639\services\windows-x86-skypekit.exe (.not file.) =>PUP.Optional.Beamrise
O87 - FAEL: "{DA9EBAA0-B107-4199-8BAA-6D79815A21DE}" [In-None-P6-TRUE] .(...) -- C:\Users\Teco\AppData\Local\Beamrise\Application\31.0.1650.7639\windows-x86-skypekit.exe (.not file.) =>PUP.Optional.Beamrise
O87 - FAEL: "{1C011B25-FF6D-46BF-AD94-8BBDCA916F35}" [Out-None-P6-TRUE] .(...) -- C:\Users\Teco\AppData\Local\Beamrise\Application\31.0.1650.7639\windows-x86-skypekit.exe (.not file.) =>PUP.Optional.Beamrise
O87 - FAEL: "{308810D4-B398-4E64-8E48-47562212BB45}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{0798B3A1-4CE0-47D1-B96F-E76F1A569142}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{81A1CA6F-A149-4A74-A4CF-96BA205CA0F9}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{C7A87592-AF26-43BD-A03D-5ED3620080E1}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{E76B243A-07CD-430E-8F85-4486B8C1AF60}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{BF205D80-04FC-43E6-999B-25E57E654CBB}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{3D70393E-F375-4801-A9F3-BF37E55F245C}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{07304FA0-08FF-4D1E-8838-E212F9DA5A76}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "TCP Query User{E8DDDFE6-F7D4-4258-A395-E43A8A1D84BD}C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe (.not file.)
O87 - FAEL: "UDP Query User{03D08603-0969-478C-9151-E36561108674}C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\konami\pro evolution soccer 2013\pes2013.exe (.not file.)
O87 - FAEL: "TCP Query User{92908F3E-41FB-4F32-990C-EC1C3AE35D9F}C:\program files (x86)\torntv.com\torntv downloader.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\torntv.com\torntv downloader.exe (.not file.) =>PUP.Optional.TornTV
O87 - FAEL: "UDP Query User{6FF4E7FF-797A-492D-A3C2-E1E38D775371}C:\program files (x86)\torntv.com\torntv downloader.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\torntv.com\torntv downloader.exe (.not file.) =>PUP.Optional.TornTV
O87 - FAEL: "{82857210-37F5-4249-9BDA-ECA84559216E}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2012\pes2012.exe (.not file.)
O87 - FAEL: "{F209534E-68BA-48EF-83BE-DEB1FB47DC85}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2012\pes2012.exe (.not file.)
O87 - FAEL: "TCP Query User{F51DAC23-53A8-42D5-B363-CF2D6EE53A85}C:\program files (x86)\konami\pro evolution soccer 2011\pes2011.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\konami\pro evolution soccer 2011\pes2011.exe (.not file.)
O87 - FAEL: "UDP Query User{BD2BB1BA-452C-4330-8023-7E241914B7D9}C:\program files (x86)\konami\pro evolution soccer 2011\pes2011.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\konami\pro evolution soccer 2011\pes2011.exe (.not file.)
O87 - FAEL: "{9094BA06-9084-4636-8EF7-BB522E5EBDF8}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{669E2739-31C0-4408-8076-708C1703D29C}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico

---\\ Serviços não Microsoft (SR=Executados, SS=Parados) (23) - 18s

SS - Disabled [2014/01/31 16:46:12] [ 257416] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ©
SS - Disabled [2013/06/14 06:33:42] [ 1281640] AFBAgent (AFBAgent) . (.ASUSTeK Computer Inc..) - C:\Windows\system32\FBAgent.exe ©
SS - Auto [2015/09/10 01:38:12] [ 488696] Application Manager 3.57.4713165 (AppMgr3.57.4713165) . (...) - C:\ProgramData\AppMgr3.57.4713165\AppMgr.exe
SS - Disabled [2012/10/05 19:55:50] [ 110976] ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe ©
SS - Disabled [2012/04/13 14:14:00] [ 277120] ASUS InstantOn Service (ASUS InstantOn) . (.ASUS.) - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe ©
SS - Disabled [2012/12/19 03:10:38] [ 72192] Asus WebStorage Windows Service (Asus WebStorage Windows Service) . (.Copyright © 2012.) - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
SS - Disabled [2011/11/21 18:19:50] [ 96896] ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe ©
SS - Disabled [2012/12/13 19:14:24] [ 277616] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe ©
SS - Disabled [2015/09/07 08:06:25] [ 142792] DNS Helper (DNSSVC) . (...) - C:\Users\Teco\AppData\Roaming\DNSHelper\DNSSVC.exe
SS - Disabled [2010/10/12 14:59:12] [ 206072] GamesAppService (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe ©
SS - Auto [2015/09/10 14:06:30] [ 144200] Serviço do Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Demand [2015/09/10 14:06:30] [ 144200] Serviço do Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Disabled [2012/04/24 18:37:56] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe ©
SS - Disabled [2012/09/13 00:59:08] [ 2466448] IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe ©
SS - Disabled [2012/04/20 18:16:12] [ 635104] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe ©
SS - Disabled [2012/06/27 16:47:02] [ 129856] Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ©
SS - Disabled [2012/06/25 14:57:14] [ 166720] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ©
SS - Disabled [2015/06/23 19:04:05] [ 211968] KMS Server Service (KMSServerService) . (.My Digital Life Forums.) - C:\Windows\KMSServerService\KMS Server Service.exe
SS - Disabled [2012/07/17 18:57:20] [ 277824] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ©
SS - Disabled [2015/07/08 22:26:02] [ 173088] Net.Tcp Service Handler (NetTcpHandler) . (...) - C:\Users\Teco\AppData\Roaming\NetService\netservice.exe
SS - Disabled [2015/02/18 19:11:32] [ 315488] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe ©
SS - Disabled [2012/07/17 18:57:22] [ 365376] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ©

---\\ Claves Tracing (8) - 1s
HKLM\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASAPI32 =>PUP.Optional.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASMANCS =>PUP.Optional.TornTV
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MixVideoPlayer_RASAPI32 =>PUP.Optional.MixVideoPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MixVideoPlayer_RASMANCS =>PUP.Optional.MixVideoPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSondPro_Service_RASAPI32 =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSondPro_Service_RASMANCS =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASAPI32 =>PUP.Optional.WordSurfer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASMANCS =>PUP.Optional.WordSurfer

---\\ Scâner Aditional (64) - 0s
C:\Windows\AutoKMS\AutoKMS.exe =>HackTool.AutoKMS
C:\WINDOWS\System32\Tasks\AutoKMSCustom =>HackTool.AutoKMS
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Primary Color =>PUP.Optional.PrimaryColor
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ss8 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse
HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP =>PUP.Optional.GamesDesktop
HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKLM\SOFTWARE\Wow6432Node\istartsurfSoftware =>PUP.Optional.IsStart
HKLM\SOFTWARE\Wow6432Node\iWebar-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\iWebar-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\MediaBuzzV1 =>PUP.Optional.MediaBuzz
HKLM\SOFTWARE\Wow6432Node\MediaBuzzV1mode9081 =>PUP.Optional.MediaBuzz
HKLM\SOFTWARE\Wow6432Node\MediaPlayerVideos 1.2 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\mystarttb =>PUP.Optional.StartSearch
HKLM\SOFTWARE\Wow6432Node\Object Browser-nv =>PUP.Optional.ObjectBrowser
HKLM\SOFTWARE\Wow6432Node\Object Browser-nv-ie =>PUP.Optional.ObjectBrowser
HKLM\SOFTWARE\Wow6432Node\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\Primary Color =>PUP.Optional.PrimaryColor
HKLM\SOFTWARE\Wow6432Node\Sm23mS-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Sm23mS-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ss8-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ss8-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive
HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue
HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro
HKLM\SOFTWARE\Wow6432Node\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer
HKCU\SOFTWARE\BrowserApp2.1 =>PUP.Optional.CrossRider
HKCU\SOFTWARE\BrowserApp2.1-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\BrowserApp2.1-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV06.09 =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV06.09-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV06.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Crossbrowse =>PUP.Optional.CrossBrowse
HKCU\SOFTWARE\CrossBrowser =>PUP.Optional.CrossBrowser
HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKCU\SOFTWARE\iWebar-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Object Browser-nv =>PUP.Optional.ObjectBrowser
HKCU\SOFTWARE\Object Browser-nv-ie =>PUP.Optional.ObjectBrowser
HKCU\SOFTWARE\Primary Color =>PUP.Optional.PrimaryColor
HKCU\SOFTWARE\Probit Software =>PUP.Optional.ProbitSoftware
HKCU\SOFTWARE\Sm23mS-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Sm23mS-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ss8-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ss8-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\tstamptoken =>PUP.Optional.MaxComputerCleaner
HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
C:\Program Files (x86)\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic
C:\ProgramData\AppMgr3.57.4713165 =>PUP.Optional.Generic
C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
C:\WINDOWS\Prefetch\ANYPROTECT.EXE-53752276.pf =>PUP.Optional.AnyProtect
C:\WINDOWS\Prefetch\OLBPRE.EXE-5FD45ACB.pf =>PUP.Optional.MyPCBackup
HKLM64\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASAPI32 =>PUP.Optional.TornTV
HKLM64\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASMANCS =>PUP.Optional.TornTV
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MixVideoPlayer_RASAPI32 =>PUP.Optional.MixVideoPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MixVideoPlayer_RASMANCS =>PUP.Optional.MixVideoPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSondPro_Service_RASAPI32 =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSondPro_Service_RASMANCS =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASAPI32 =>PUP.Optional.WordSurfer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASMANCS =>PUP.Optional.WordSurfer

---\\ Resumo dos elementos encontrados na sua estação de trabalho (27) - 0s
http://www.nicolascoolman.fr/blog =>PUP.Optional.SpaceSoundPro
http://www.nicolascoolman.fr/pup-probitsoftware/ =>PUP.Optional.ProbitSoftware
http://www.nicolascoolman.fr/trojan-autokms/ =>HackTool.AutoKMS
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.PrimaryColor
http://www.nicolascoolman.fr/blog =>PUP.Optional.Generic
http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowse
http://www.nicolascoolman.fr/blog =>PUP.Optional.GamesDesktop
http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate
http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowserExtensions
http://www.nicolascoolman.fr/pup-isstart/ =>PUP.Optional.IsStart
http://www.nicolascoolman.fr/pup-mediabuzz/ =>PUP.Optional.MediaBuzz
http://www.nicolascoolman.fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch
http://www.nicolascoolman.fr/pup-objectbrowser/ =>PUP.Optional.ObjectBrowser
http://www.nicolascoolman.fr/spyware-agenceexclusive/ =>PUP.Optional.AgenceExclusive
http://www.nicolascoolman.fr/blog =>PUP.Optional.Uniblue
http://www.nicolascoolman.fr/blog =>PUP.Optional.WdsManPro
http://www.nicolascoolman.fr/blog =>PUP.Optional.WordSurfer
http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowser
http://www.nicolascoolman.fr/blog =>PUP.Optional.MaxComputerCleaner
http://www.nicolascoolman.fr/pup-anyprotect/ =>PUP.Optional.AnyProtect
http://www.nicolascoolman.fr/pup-mypcbackup/ =>PUP.Optional.MyPCBackup
http://www.nicolascoolman.fr/blog =>PUP.Optional.DllFilesFixer
http://www.nicolascoolman.fr/hijacker-beamrise/ =>PUP.Optional.Beamrise
http://www.nicolascoolman.fr/pup-kmspico/ =>HackTool.KMSpico
http://www.nicolascoolman.fr/hijacker-torntv/ =>PUP.Optional.TornTV
http://www.nicolascoolman.fr/blog =>PUP.Optional.MixVideoPlayer

~ End of the scan, 23621 items in 168 seconds (922)(0)()

Publicité


Signaler le contenu de ce document

Publicité