~ ZHPDiag v2015.9.10.139 Por Nicolas Coolman (2015/09/10) ~ iniciado por robério (Administrator) (2015/09/11 14:37:57) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Status da versão: Version OK ~ Modo: Scanner ~ Relatório: C:\Users\rober\Desktop\ZHPDiag.txt ~ Relatório: C:\Users\rober\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Inicialização do sistema: Normal (Normal boot) Windows 10 Pro Insider Preview, 64-bit (Build 10532) ---\\ Navegadores Internet (1) - 0s MSIE: Internet Explorer v11.0.10532.0 ---\\ Informações sobre os produtos Windows (3) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ Softwares de proteçao do sistema (1) - 1s Windows Defender W10 (Activate) ---\\ Softwares de proteçao do sistema (Supérfluo) (1) - 1s SpyHunter v4.17.6.4336 ---\\ Monitoramento dos softwares (1) - 1s Adobe Flash Player 18 PPAPI ---\\ Informações sobre o sistema (6) - 0s ~ Operating System: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 8333.876 MB (70% free) ~ System Restore: Activé (Enable) ~ System drive C: has 29 GB free of 113 GB ---\\ Modo de conexão ao sistema (3) - 0s ~ Computer Name: DESKTOP-I6EPLQV ~ User Name: robério ~ Logged in as Administrator ---\\ Enumeração das unidades dos discos (5) - 0s ~ Drive C: has 29 GB free of 113 GB (System) ~ Drive D: has 0 GB free of 0 GB ~ Drive E: has 11 GB free of 53 GB ~ Drive F: has 72 GB free of 439 GB ~ Drive G: has 118 GB free of 459 GB ---\\ Estado do Centro de Segurança do Windows (7) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Pesquisa particular de ficheiros genéricos (24) - 1s [MD5.382F9D30C69656B1499ECF6841520CE0] - (.Microsoft Corporation - Windows Explorer.) () -- C:\WINDOWS\Explorer.exe [4551528] © [MD5.7C7C5FB5D7021FA4EBD953768BB9AFD2] - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [59392] © [MD5.FE00F75CBECE4A63D3306CF96D2C2026] - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) () -- C:\WINDOWS\System32\Wininit.exe [287336] © [MD5.653BDBA73D91E32B889D91AC0C5507BB] - (.Microsoft Corporation - Internet Extensions para Win32.) () -- C:\WINDOWS\System32\wininet.dll [2740736] © [MD5.CD68FD731AEAC42672F505E73394E067] - (.Microsoft Corporation - Aplicativo de Logon do Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [583680] © [MD5.AAD14203651511CFBB71799E0A31E6A5] - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) () -- C:\WINDOWS\System32\sppcomapi.dll [430592] © [MD5.06A04A1C4EBE6BEC6D5C805EE3D812C8] - (.Microsoft Corporation - DLL da API de cliente DNS.) () -- C:\WINDOWS\System32\dnsapi.dll [685032] © =>Hijacker.Hosts [MD5.47CE2BCBFBBAE826FA3A380D20E56C58] - (.Microsoft Corporation - DLL da API de cliente DNS.) () -- C:\WINDOWS\Syswow64\dnsapi.dll [536232] © =>Hijacker.Hosts [MD5.07607AC2451D0955F7B28B8C9853B8A9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [577512] © [MD5.B7FBA56621EE0694E6EF95974B37DCAB] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [28648] © [MD5.40734B5D07EA99D545DF2D67967A5ECA] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] © [MD5.DD0C966E9A662EEA64A3BD49D0580981] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080] © [MD5.0EC5F36191A0A4766823E28461694F27] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [138240] © [MD5.DFF17FDCFC80B4BBE58924AC0705C041] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [78848] © [MD5.4B60E443292779A810183AA19EC053F3] - (.Microsoft Corporation - Driver de porta i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] © [MD5.3C629F2F66776B9084C6332B10046479] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] © [MD5.D66AEB98137D6A1D5CCFBB8E2FA0721C] - (.Microsoft Corporation - Minirdr SMB do Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [438248] © [MD5.4652435CD1B1BAD2F2A520703107EA4A] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [274432] © [MD5.CBB3B2317878E366349CEBBE59048E9D] - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2112488] © [MD5.CC50A33BA34C84EE18348E39FDF78E39] - (.Microsoft Corporation - Driver de porta paralela.) () -- C:\WINDOWS\System32\drivers\Parport.sys [96768] © [MD5.03B97E51E99BA3E37AF636346FFB673D] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] © [MD5.89018F293E995C1C5ED3F7B9E2F8D1F1] - (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Micros.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128] © [MD5.56A5F32754D616CB3A5CC3CFD5DF67BC] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [117224] © [MD5.C6585AAF385B557C0ABA43EF9D6941FC] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [381928] © ---\\ Processos lançados (39) - 1s [MD5.ACD4AF1B9D6E6C0C5BE470E5CF313FE6] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [814880] [PID.828] © [MD5.935CD218C06721994ED48349361467F9] - (.GAS Tecnologia - G-Buster Browser Defense - Service.) -- C:\Program Files (x86)\GbPlugin\GbpSv.exe [555320] [PID.1672] [MD5.6BF0147A7A924E5A3AE049A95ECC9B34] - (.AMD - AMD External Events Service Module.) -- C:\WINDOWS\system32\atiesrxx.exe [246784] [PID.1772] © [MD5.B7CC6DB515E9347EEC2FC19D4C09A962] - (.AMD - AMD External Events Client Module.) -- C:\WINDOWS\system32\atieclxx.exe [672768] [PID.1800] © [MD5.337FA50FFDED5E2BC94B36BF625AB681] - (.IObit - Product Updater.) -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472] [PID.2084] © [MD5.139AEA629F9857FFD9D8312BE8F97389] - (.Autodesk Inc. - Autodesk Application Manager.) -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1129864] [PID.2092] [MD5.E789ACAE130B5219BDF4CDA0E726E5D5] - (...) -- C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\knsr701C.tmpfs [1383936] [PID.2100] =>PUP.Optional.CrossRider [MD5.485CBE0A862457BC1BCA099F16A96202] - (...) -- C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\hnslBAAA.tmp [203776] [PID.2112] =>PUP.Optional.CrossRider [MD5.2D517DCEBECBF12D1D49BBC71F3D752C] - (...) -- C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\jnsp9E08.tmp [181760] [PID.2128] =>PUP.Optional.CrossRider [MD5.476D9CEC2F1C57D5DDB8C2134F224866] - (.Copyright (C) 2015 - The Calendar Service.) -- C:\Program Files (x86)\CalendarTool\2.0.0.10764\CalendarServ.exe [149432] [PID.2336] [MD5.809B39A1A036C20994E68CF322A2519A] - (.DTools LIMITED - DTools.) -- C:\ProgramData\OWdsManProO\WdsManPro.exe [451720] [PID.2356] =>PUP.Optional.WdsManPro [MD5.819594D26957FF2F1A1EDFBDD556DFC8] - (.Copyright (C) 2015 - calendar Application.) -- C:\Program Files (x86)\CalendarTool\2.0.0.10764\calendar.exe [3925432] [PID.3360] [MD5.73162936309F3D1ADBE47602EFF47F17] - (.Copyright © 2005-2014 by Alexey Nicolaychuk aka Unwin - RTSS.) -- C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [197632] [PID.3408] [MD5.22544393B0C597DED7686D4E8F851A23] - (.IObit - Performance Monitor.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [1773856] [PID.3440] © [MD5.935CD218C06721994ED48349361467F9] - (.GAS Tecnologia - G-Buster Browser Defense - Service.) -- C:\Program Files (x86)\GbPlugin\GbpSv.exe [555320] [PID.4124] [MD5.6680E86F4A209B583F8E8A968E16B13F] - (...) -- C:\Users\rober\AppData\Local\gmsd_br_005010084\upgmsd_br_005010084.exe [3315344] [PID.4312] [MD5.3A66FFD5CB7842772EF1B822A1A1F01F] - (.Copyright © 2013-2014 by Alexey Nicolaychuk aka Unwin - EncoderServer.) -- C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe [26112] [PID.3692] [MD5.9A4C783A7616D7812350345D3213AF77] - (.Copyright © 2012-2014 by Alexey Nicolaychuk aka Unwin - RTSS.) -- C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe [88576] [PID.3892] [MD5.CB6F337F5D7FD57E422D0A533FE807EA] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe [307400] [PID.5164] © [MD5.9AC10DF42CC1E811BB8608A0B609A7D0] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552] [PID.5192] © [MD5.AA93F6052984CA2FE8EB771535CB2920] - (.Raptr, Inc - Raptr Desktop App.) -- C:\Program Files (x86)\Raptr\raptr.exe [67344] [PID.5388] © [MD5.EC167B2F4784652C89C9DBCA5ABA5AE2] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Host application.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe [307912] [PID.5440] © [MD5.6FE45A21163CBBC996247499E785F557] - (.Raptr, Inc - Raptr Desktop App.) -- C:\Program Files (x86)\Raptr\raptr_im.exe [46352] [PID.5900] © [MD5.B0D709EF53A34AEF9EBEC9F024F857A5] - (.Raptr Inc. - Elevation Proxy.) -- C:\Program Files (x86)\Raptr\raptr_ep64.exe [149760] [PID.3432] © [MD5.1E1AC1BDED0704868199E519F74B80BB] - (.IObit - .) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe [187168] [PID.3428] © [MD5.07782C388EDDB13CB0A1040F7E1DDCDC] - (.IObit - Real-time Protector.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\RealTimeProtector.exe [1106720] [PID.4056] © [MD5.BA6F01FDDB4C5106CE58B48F1BCD97B1] - (.IObit - Uninstall Programs.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [8022816] [PID.2052] © [MD5.153F088DFDB3F940AD9DAEB04A3ACC4D] - (.SoftBrain Technologies Ltd. - SmartWeb helper.) -- C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe [270368] [PID.8028] =>PUP.Optional.SmartWebSearch [MD5.44069C2AC699C8DAD80A96FB1C8DFE57] - (.SoftBrain Technologies Ltd. - SmartWeb Application.) -- C:\Users\rober\AppData\Local\SmartWeb\SmartWebApp.exe [557088] [PID.8124] =>PUP.Optional.SmartWebSearch [MD5.C8CE083EAA1E2996DE71DA140DA45014] - (...) -- C:\Program Files (x86)\OLBPre\OLBPre.exe [2471936] [PID.3600] =>PUP.Optional.MyPCBackup [MD5.4580AC6F8ADADB5CE9F296F7FF5B15DD] - (.TODO: <公司名> - TODO: <文件说明>.) -- C:\Program Files (x86)\SFK\SSFK.exe [450048] [PID.7428] [MD5.7537122E032DD3B52AADF467B3E8553A] - (...) -- C:\Program Files (x86)\SFK\SFKEX64.exe [123392] [PID.3672] [MD5.E3C1014B084BB9E7C44797162DE28D00] - (.Copyright (C) 2014 - .) -- C:\Program Files\WajaInternetEn\wajam_64.exe [2137088] [PID.6872] =>PUP.Optional.Wajam [MD5.057B59B55C64A447C257C79F49142A6A] - (.Copyright (C) 2014 - .) -- c:\program files\wajainterneten\wajam.exe [1737728] [PID.2908] =>PUP.Optional.Wajam [MD5.E3C1014B084BB9E7C44797162DE28D00] - (.Copyright (C) 2014 - .) -- c:\program files\wajainterneten\wajam_64.exe [2137088] [PID.7648] =>PUP.Optional.Wajam [MD5.C23D4585B9BFE9CF49B4445638B9D35A] - (.Uniblue Systems Limited - Uniblue SpeedUpMyPC.) -- C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [4140888] [PID.3820] =>PUP.Optional.SpeedUpMyPC [MD5.9586BA92B069D03A9D3484248F2058EC] - (.InstallMoon - GoHD exe.) -- C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6.exe [1375824] [PID.6180] =>PUP.Optional.CrossRider [MD5.CE63F25AE041877635695FCDC241CF11] - (.Adobe Systems Incorporated - Adobe® Flash® Player Utility.) -- C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe [862696] [PID.7656] © [MD5.886A7A8D794D4C8DB2D8ADC9990CCD7D] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\rober\Downloads\ZHPDiag3.exe [1925632] [PID.2488] © ---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (5) - 0s P2 - FPN: [HKCU] [@iqiyi.com/npWebPlayer] - (.爱奇艺公司.) -- C:\IQIYI Video\LStyle\npWebPlayer.dll =>PUP.Optional.IQIYIVideo P2 - FPN: [HKLM] [@iqiyi.com/npclient] - (.iQiyi.com.) -- C:\IQIYI Video\LStyle\npclient.dll =>PUP.Optional.IQIYIVideo P2 - FPN: [HKLM] [@iqiyi.com/npWebPlayer] - (.爱奇艺公司.) -- C:\IQIYI Video\LStyle\npWebPlayer.dll =>PUP.Optional.IQIYIVideo P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=10] - (.globalUpdate.) -- C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll =>PUP.Optional.GlobalUpdate P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=4] - (.globalUpdate.) -- C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll =>PUP.Optional.GlobalUpdate ---\\ Opera, Plugins,Arranque,Pesquisa (2) - 0s B2 - EXT: [GoHD] C:\Users\rober\AppData\Roaming\Opera Software\Opera Stable\Extensions\fijhlnmmmgflacagjecncpmpnhjieggk B2 - EXT: [CinemaPlus-3.2cV11.09] C:\Users\rober\AppData\Roaming\Opera Software\Opera Stable\Extensions\papbadoldddalgcjcicnikcfenodpghp ---\\ Internet Explorer, Arranque, Pesquisa, Phishing (16) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://br.search.yahoo.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/ =>PUP.Optional.Browser R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/ =>PUP.Optional.Browser R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/ =>PUP.Optional.Omniboxes R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer, Gestão do Proxy (2) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 ---\\ Análise das linhas, Carregamento Automático de programas (3) - 0s F2 - REG:system.ini: UserInit= F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet= ---\\ Redireção do ficheiro Hosts (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Objects do navegador (3) - 0s O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814} . (.IObit - Uninstall for explorer.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll © O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll © O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll © ---\\ Aplicações iniciadas por registo & pastas (23) - 0s O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\rober\AppData\Local\Microsoft\OneDrive\OneDrive.exe © O4 - HKCU\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe © O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] . (.Disc Soft Ltd - DAEMON Tools Ultra Agent.) -- C:\Program Files\DAEMON Tools Ultra\DTAgent.exe © O4 - HKCU\..\Run: [AdobeBridge] (Orphean) O4 - HKCU\..\Run: [YeaInstaller] . (.TZ - Generic Host Process for Win32 Services.) -- C:\Users\rober\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_168.exe O4 - HKLM\..\Wow6432Node\Run: [Raptr] . (.Raptr, Inc - Raptr Desktop App.) -- C:\Program Files (x86)\Raptr\raptrstub.exe © O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe © O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe © O4 - HKLM\..\Wow6432Node\Run: [ADSKAppManager] . (.Autodesk Inc. - Autodesk Application Manager.) -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe O4 - HKLM\..\Wow6432Node\Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe © O4 - HKLM\..\Wow6432Node\Run: [AdobeCS6ServiceManager] . (.Adobe Systems Incorporated - Adobe CS6 Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe © O4 - HKLM\..\Wow6432Node\Run: [wenguanjia] C:\Users\rober\AppData\Roaming\wenguanjia\PiLoader.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [SmartWeb] . (.SoftBrain Technologies Ltd. - SmartWeb helper.) -- C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe =>PUP.Optional.SmartWebSearch O4 - HKLM\..\Wow6432Node\RunOnce: [upgmsd_br_005010084.exe] . (...) -- C:\Users\rober\AppData\Local\gmsd_br_005010084\upgmsd_br_005010084.exe O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATII4E.EXE © O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATII4E.EXE © O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe © O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe © O4 - HKUS\S-1-5-21-4170433591-1114984897-512042225-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\rober\AppData\Local\Microsoft\OneDrive\OneDrive.exe © O4 - HKUS\S-1-5-21-4170433591-1114984897-512042225-1001\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe © O4 - HKUS\S-1-5-21-4170433591-1114984897-512042225-1001\..\Run: [DAEMON Tools Ultra Agent] . (.Disc Soft Ltd - DAEMON Tools Ultra Agent.) -- C:\Program Files\DAEMON Tools Ultra\DTAgent.exe © O4 - HKUS\S-1-5-21-4170433591-1114984897-512042225-1001\..\Run: [AdobeBridge] (Orphean) O4 - HKUS\S-1-5-21-4170433591-1114984897-512042225-1001\..\Run: [YeaInstaller] . (.TZ - Generic Host Process for Win32 Services.) -- C:\Users\rober\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_168.exe ---\\ Atalhos globais Startup (42) - 2s O4 - GS\Desktop [Administrador]: AnyProtect.lnk . (.AnyProtect.com - AnyProtect.) C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe =>PUP.Optional.AnyProtect O4 - GS\Desktop [Administrador]: Facebook.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [Administrador]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [Administrador]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Desktop [Administrador]: SpyHunter.lnk . (.Enigma Software Group USA, LLC. - SpyHunter4 application.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe =>.Superfluous.SpyHunter O4 - GS\Quicklaunch [Administrador]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [Administrador]: Search The Internet.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [Administrador]: SpeedUpMyPC.lnk . (.Uniblue Systems Limited - Uniblue SpeedUpMyPC.) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC O4 - GS\Startup [Administrador]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Startup [Administrador]: SmartWeb.lnk . (.SoftBrain Technologies Ltd. - SmartWeb helper.) C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe =>PUP.Optional.SmartWebSearch O4 - GS\Desktop [Convidado]: AnyProtect.lnk . (.AnyProtect.com - AnyProtect.) C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe =>PUP.Optional.AnyProtect O4 - GS\Desktop [Convidado]: Facebook.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [Convidado]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [Convidado]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Desktop [Convidado]: SpyHunter.lnk . (.Enigma Software Group USA, LLC. - SpyHunter4 application.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe =>.Superfluous.SpyHunter O4 - GS\Quicklaunch [Convidado]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [Convidado]: Search The Internet.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [Convidado]: SpeedUpMyPC.lnk . (.Uniblue Systems Limited - Uniblue SpeedUpMyPC.) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC O4 - GS\Startup [Convidado]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Startup [Convidado]: SmartWeb.lnk . (.SoftBrain Technologies Ltd. - SmartWeb helper.) C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe =>PUP.Optional.SmartWebSearch O4 - GS\Desktop [DefaultAccount]: AnyProtect.lnk . (.AnyProtect.com - AnyProtect.) C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe =>PUP.Optional.AnyProtect O4 - GS\Desktop [DefaultAccount]: Facebook.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [DefaultAccount]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [DefaultAccount]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Desktop [DefaultAccount]: SpyHunter.lnk . (.Enigma Software Group USA, LLC. - SpyHunter4 application.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe =>.Superfluous.SpyHunter O4 - GS\Quicklaunch [DefaultAccount]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [DefaultAccount]: Search The Internet.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [DefaultAccount]: SpeedUpMyPC.lnk . (.Uniblue Systems Limited - Uniblue SpeedUpMyPC.) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC O4 - GS\Startup [DefaultAccount]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Startup [DefaultAccount]: SmartWeb.lnk . (.SoftBrain Technologies Ltd. - SmartWeb helper.) C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe =>PUP.Optional.SmartWebSearch O4 - GS\Desktop [robério]: AnyProtect.lnk . (.AnyProtect.com - AnyProtect.) C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe =>PUP.Optional.AnyProtect O4 - GS\Desktop [robério]: Facebook.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [robério]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Desktop [robério]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Desktop [robério]: SpyHunter.lnk . (.Enigma Software Group USA, LLC. - SpyHunter4 application.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe =>.Superfluous.SpyHunter O4 - GS\Quicklaunch [robério]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [robério]: Search The Internet.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\rober\AppData\local\Chromium\Application\chrome.exe => O4 - GS\Quicklaunch [robério]: SpeedUpMyPC.lnk . (.Uniblue Systems Limited - Uniblue SpeedUpMyPC.) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC O4 - GS\Startup [robério]: MyPC Backup.lnk . (...) C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup O4 - GS\Startup [robério]: SmartWeb.lnk . (.SoftBrain Technologies Ltd. - SmartWeb helper.) C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe =>PUP.Optional.SmartWebSearch O4 - GS\CommonDesktop [Public]: Advanced System~Protector.lnk . (.Copyright - ASP.) C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe =>PUP.Optional.AdvancedSystemProtector O4 - GS\CommonDesktop [Public]: SpeedUpMyPC.lnk . (.Uniblue Systems Limited - Uniblue SpeedUpMyPC.) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC ---\\ Alteração Dominio/Clientes DNS (2) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ---\\ Protocolo adicional (21) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll © O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll © O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © ---\\ Valor do Registo AppInit_DLLs e sub-chaves Winlogon Notify (1) - 0s O20 - AppInit_DLLs: . (...) - C:\ProgramData\FlashBeat\FlashBeat64.dll (.not file.) =>PUP.Optional.FlashBeat ---\\ Serviços NT não Microsoft e não desativados (14) - 1s O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) . (.Autodesk Inc. - Autodesk Application Manager.) - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) . (.IObit - Advanced SystemCare Service.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe © O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe © O23 - Service: Presentation Default (bebymoju) . (...) - C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\knsr701C.tmpfs =>PUP.Optional.CrossRider O23 - Service: Gbp Service (GbpSv) . (.GAS Tecnologia - G-Buster Browser Defense - Service.) - C:\Program Files (x86)\GbPlugin\GbpSv.exe O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate - globalUpdate Update.) - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe =>PUP.Optional.GlobalUpdate O23 - Service: CD Feature (gyvixodu) . (...) - C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\hnslBAAA.tmp =>PUP.Optional.CrossRider O23 - Service: Disk Low-res (lehicewu) . (...) - C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\jnsp9E08.tmp =>PUP.Optional.CrossRider O23 - Service: LiveUpdate (LiveUpdateSvc) . (.IObit - Product Updater.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe © O23 - Service: SpyHunter 4 Service (SpyHunter 4 Service) . (.Enigma Software Group USA, LLC. - Service scanner interface.) - C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe =>.Superfluous.SpyHunter O23 - Service: SSFK (SSFK) . (.TODO: <公司名> - TODO: <文件说明>.) - C:\Program Files (x86)\SFK\SSFK.exe =>PUP.Optional.MyWebSearch O23 - Service: The Calendar Service (TheCalendarService) . (.Copyright (C) 2015 - The Calendar Service.) - C:\Program Files (x86)\CalendarTool\2.0.0.10764\CalendarServ.exe O23 - Service: WajaInternetEn Monitor (WajaInternetEn Monitor) . (.Copyright (C) 2014 - .) - C:\Program Files\WajaInternetEn\wajam_64.exe =>PUP.Optional.Wajam O23 - Service: @C:\Program Files (x86)\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (.not file.) ---\\ Tarefas planificadas automaticamente (141) - 5s [MD5.9586BA92B069D03A9D3484248F2058EC] [APT] [1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6] (.InstallMoon.) -- C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6.exe [1375824] =>PUP.Optional.CrossRider [MD5.F62E7A0082212CAE7B35F7563186BAE7] [APT] [1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7] (.InstallMoon.) -- C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7.exe [1022544] =>PUP.Optional.CrossRider [MD5.59ACD18CD921748D44D3558390677A35] [APT] [1fd558bf-2f63-4070-8891-3e2e3f82401e-11] (.InstallMoon.) -- C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-11.exe [1319504] =>PUP.Optional.CrossRider [MD5.7D0C9A286F47A110B2E3C122168835C0] [APT] [1fd558bf-2f63-4070-8891-3e2e3f82401e-5] (.InstallMoon.) -- C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-5.exe [1075792] =>PUP.Optional.CrossRider [MD5.011BD8A49AF856E8A8EE32652D1CFC05] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [268976] © [MD5.8BB574F9AB3B149AC82C8EBECAF54A3C] [APT] [Advanced System~Protector] (.Copyright.) -- C:\Program Files (x86)\ASP\AspManager.exe [480584] =>PUP.Optional.AdvancedSystemProtector [MD5.98C89B9CAE967F127779C94E2AD93410] [APT] [Advanced System~Protector_startup] (.Copyright.) -- C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe [6432072] =>PUP.Optional.AdvancedSystemProtector [MD5.2691439FAC40F46C937BB684A3AE2E0F] [APT] [APSnotifierPP1] (.AnyProtect.com.) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [6434816] =>PUP.Optional.AnyProtect [MD5.2691439FAC40F46C937BB684A3AE2E0F] [APT] [APSnotifierPP2] (.AnyProtect.com.) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [6434816] =>PUP.Optional.AnyProtect [MD5.2691439FAC40F46C937BB684A3AE2E0F] [APT] [APSnotifierPP3] (.AnyProtect.com.) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [6434816] =>PUP.Optional.AnyProtect [MD5.22544393B0C597DED7686D4E8F851A23] [APT] [ASC8_PerformanceMonitor] (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [1773856] © [MD5.EE24E1D4387E9851E1157EFEAEF3BA1C] [APT] [ASC8_SkipUac_rober] (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [5353760] © [MD5.EE24E1D4387E9851E1157EFEAEF3BA1C] [APT] [ASC8_SkipUac_rob‚rio] (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [5353760] © [MD5.0A1E0A6E2CBD34518E90839446C95560] [APT] [ASP] (.Systweak Inc.) -- C:\Program Files (x86)\RCP\systweakasp.exe [597344] =>PUP.Optional.Systweak [MD5.00000000000000000000000000000000] [APT] [c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6] (...) -- C:\Program Files (x86)\I - Cinema\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7] (...) -- C:\Program Files (x86)\I - Cinema\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11] (...) -- C:\Program Files (x86)\I - Cinema\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5] (...) -- C:\Program Files (x86)\I - Cinema\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.2CA9478488AD609B7761ED95A5C5A93D] [APT] [Convertor] (...) -- C:\Program Files (x86)\Convertor\Convertor.exe [156240] [MD5.00000000000000000000000000000000] [APT] [crash_service] (...) -- C:\Users\rober\AppData\Local\BoBrowser\Application\crash_service.exe (.not file.) [0] =>PUP.Optional.BoBrowser [MD5.5556C54070E16F917393812335381087] [APT] [Driver Booster Scan] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [67904] © [MD5.37D941D7C294F2314EAC30F0FFAC8106] [APT] [Driver Booster SkipUAC (rober)] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [4436800] © [MD5.37D941D7C294F2314EAC30F0FFAC8106] [APT] [Driver Booster SkipUAC (rob‚rio)] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [4436800] © [MD5.0AEEF3E86850ADF3626DA01CE7E08D1E] [APT] [Driver Booster Update] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [1440576] © [MD5.7477F7B4C06369C94E702F5779E00E61] [APT] [fe88b57d-f774-4a30-a287-8727f629acfa-1-6] (.CinemaPlus-3.2cV11.09.) -- C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-1-6.exe [1317456] =>PUP.Optional.CrossRider [MD5.BFFB47F7CFACEF32BF3DBD318359E52A] [APT] [fe88b57d-f774-4a30-a287-8727f629acfa-1-7] (.CinemaPlus-3.2cV11.09.) -- C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-1-7.exe [975440] =>PUP.Optional.CrossRider [MD5.2EDE391EA83E94DCF4A70AC559D512E1] [APT] [fe88b57d-f774-4a30-a287-8727f629acfa-11] (.CinemaPlus-3.2cV11.09.) -- C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-11.exe [1390672] =>PUP.Optional.CrossRider [MD5.C2AE737EA4534D3C3E0B402F5AD2E5B0] [APT] [fe88b57d-f774-4a30-a287-8727f629acfa-5] (.CinemaPlus-3.2cV11.09.) -- C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-5.exe [1013840] =>PUP.Optional.CrossRider [MD5.3C14AAE26EA06BADAC98520773772CEB] [APT] [globalUpdateUpdateTaskMachineCore] (.globalUpdate.) -- C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608] =>PUP.Optional.GlobalUpdate [MD5.3C14AAE26EA06BADAC98520773772CEB] [APT] [globalUpdateUpdateTaskMachineUA] (.globalUpdate.) -- C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608] =>PUP.Optional.GlobalUpdate [MD5.00000000000000000000000000000000] [APT] [GPUKLMB1] (...) -- C:\ProgramData\FlashBeat\FlashBeat.exe (.not file.) [0] =>PUP.Optional.FlashBeat [MD5.6DFC8142617B9221806C12539BB4FC45] [APT] [Internet Quick Access Updater] (.Copyright © 2014.) -- C:\Users\rober\AppData\Local\Chromium\Application\45.0.2433.0\Installer\updater\updater.exe [541696] =>PUP.Optional.InternetQuickAccess [MD5.C8CE083EAA1E2996DE71DA140DA45014] [APT] [LaunchPreSignup] (...) -- C:\Program Files (x86)\OLBPre\OLBPre.exe [2471936] =>PUP.Optional.MyPCBackup [MD5.495F41C90DD214C7C93A53F7053679D7] [APT] [MSIAfterburner] (.Copyright © 2009-2015 Alexey Nicolaychuk aka Unwinder.) -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [578272] [MD5.00000000000000000000000000000000] [APT] [MyBrowser] (...) -- C:\Program Files (x86)\MyBrowser\MyBrowser\Application\utility.exe (.not file.) [0] [MD5.6DFC8142617B9221806C12539BB4FC45] [APT] [MyPC Backup Updater] (.Copyright © 2014.) -- C:\Program Files (x86)\OLBPre\updater\updater.exe [541696] =>PUP.Optional.MyPCBackup [MD5.00000000000000000000000000000000] [APT] [PostPoneInstall] (...) -- C:\Users\rober\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe (.not file.) [0] [MD5.A1A134C19579C3198ACDC743EBB4942B] [APT] [RegClean Pro] (...) -- C:\Program Files (x86)\RCP\RegCleanPro.exe [8732952] =>PUP.Optional.RegistryPowerCleaner [MD5.A1A134C19579C3198ACDC743EBB4942B] [APT] [RegClean Pro_DEFAULT] (...) -- C:\Program Files (x86)\RCP\RegCleanPro.exe [8732952] =>PUP.Optional.RegistryPowerCleaner [MD5.A1A134C19579C3198ACDC743EBB4942B] [APT] [RegClean Pro_UPDATES] (...) -- C:\Program Files (x86)\RCP\RegCleanPro.exe [8732952] =>PUP.Optional.RegistryPowerCleaner [MD5.00000000000000000000000000000000] [APT] [Rocha] (...) -- C:\Program Files\shopperz100920151159\Fockut.bat (.not file.) [0] =>PUP.Optional.Shopperz [MD5.73162936309F3D1ADBE47602EFF47F17] [APT] [RTSS] (.Copyright © 2005-2014 by Alexey Nicolaychuk aka Unwin.) -- C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [197632] [MD5.00000000000000000000000000000000] [APT] [Run_Bobby_Browser] (...) -- C:\Users\rober\AppData\Local\BoBrowser\Application\bobrowser.exe (.not file.) [0] =>PUP.Optional.BoBrowser [MD5.153F088DFDB3F940AD9DAEB04A3ACC4D] [APT] [SmartWeb Upgrade Trigger Task] (.SoftBrain Technologies Ltd..) -- C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe [270368] =>PUP.Optional.SmartWebSearch [MD5.C23D4585B9BFE9CF49B4445638B9D35A] [APT] [SpeedUpMyPC Maintenance] (.Uniblue Systems Limited.) -- C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [4140888] =>PUP.Optional.SpeedUpMyPC [MD5.C23D4585B9BFE9CF49B4445638B9D35A] [APT] [SpeedUpMyPC Startup] (.Uniblue Systems Limited.) -- C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [4140888] =>PUP.Optional.SpeedUpMyPC [MD5.49FDC02715122739B27BE142D9D6CCF5] [APT] [SpyHunter4Startup] (.Enigma Software Group USA, LLC..) -- C:\Program Files (x86)\Enigma Software Group\SpyHunter\Spyhunter4.exe [6434176] =>.Superfluous.SpyHunter [MD5.EABCEC6D7BA3E0EA6E2A797D8731005F] [APT] [svchost] (.TZ.) -- C:\Users\rober\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_168.exe [2229760] [MD5.AB45761E2ED2DCAE20CB0AD3635EBE71] [APT] [TDKXEPIRGITQYRAS] (.All rights reserved..) -- C:\ProgramData\Service1291\Service1291.exe [436736] =>Heuristic.Graftor [MD5.00000000000000000000000000000000] [APT] [Tnuimuni] (...) -- C:\ProgramData\Tnuimuni\1.0.5.1\uenhonle.exe (.not file.) [0] =>Heuristic.PullUpdate [MD5.BA6F01FDDB4C5106CE58B48F1BCD97B1] [APT] [Uninstaller_SkipUac_rober] (.IObit.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [8022816] © [MD5.BA6F01FDDB4C5106CE58B48F1BCD97B1] [APT] [Uninstaller_SkipUac_rob‚rio] (.IObit.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [8022816] © [MD5.56B900BEC32B63EA5BA1F884A8052A3D] [APT] [updateTask] (...) -- c:/task.vbs [292] [MD5.00000000000000000000000000000000] [APT] [VLCUpdate] (...) -- C:\Users\rober\AppData\Local\VLCUpdate\vlpu.exe (.not file.) [0] [MD5.2CA9478488AD609B7761ED95A5C5A93D] [APT] [WinKit] (...) -- C:\Users\rober\AppData\Roaming\PDFConvert\SWUpdate.exe [156240] [MD5.2CA9478488AD609B7761ED95A5C5A93D] [APT] [Winsta Update] (...) -- C:\Program Files (x86)\Winsta\bin\Winsta.exe [156240] [MD5.85FCB2EBD224E405C181DAD61E6BB184] [APT] [WordSurfer Auto Updater 1.10.0.19 Core] (.Word Surfer.) -- C:\Program Files (x86)\WordSurfer_1.10.0.19\Update\WordSurferAutoUpdateClient.exe [63576] =>PUP.Optional.WordSurfer [MD5.85FCB2EBD224E405C181DAD61E6BB184] [APT] [WordSurfer Auto Updater 1.10.0.19 Pending Update] (.Word Surfer.) -- C:\Program Files (x86)\WordSurfer_1.10.0.19\Update\WordSurferAutoUpdateClient.exe [63576] =>PUP.Optional.WordSurfer [MD5.00000000000000000000000000000000] [APT] [{D9BAB2C9-5236-48c3-AF02-67E799F09BBD}{19F8DB95-4D78-4ddb-AC71-C610654FE37F}] (...) -- C:\Program Files (x86)\CalendarTool\1.3.1.10384\InstallHelper.exe (.not file.) [0] O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6 - (.InstallMoon.) -- C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6.job [3140] =>PUP.Optional.CrossRider O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7 - (.InstallMoon.) -- C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7.job [3476] =>PUP.Optional.CrossRider O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-11 - (.InstallMoon.) -- C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-11.job [5186] =>PUP.Optional.CrossRider O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-5 - (.InstallMoon.) -- C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-5.job [2448] =>PUP.Optional.CrossRider O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [902] © O39 - APT: APSnotifierPP1 - (.AnyProtect.com.) -- C:\WINDOWS\Tasks\APSnotifierPP1.job [378] =>PUP.Optional.AnyProtect O39 - APT: APSnotifierPP2 - (.AnyProtect.com.) -- C:\WINDOWS\Tasks\APSnotifierPP2.job [376] =>PUP.Optional.AnyProtect O39 - APT: APSnotifierPP3 - (.AnyProtect.com.) -- C:\WINDOWS\Tasks\APSnotifierPP3.job [376] =>PUP.Optional.AnyProtect O39 - APT: ASC8_SkipUac_rober - (.IObit.) -- C:\WINDOWS\Tasks\ASC8_SkipUac_rober.job [274] © O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6 - (...) -- C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6.job [3152] =>PUP.Optional.CrossRider O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7 - (...) -- C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7.job [3488] =>PUP.Optional.CrossRider O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11 - (...) -- C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11.job [5198] =>PUP.Optional.CrossRider O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5 - (...) -- C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5.job [2804] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-1-6 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-6.job [3174] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-1-7 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-7.job [3510] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-11 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-11.job [5220] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-5 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-5.job [2482] =>PUP.Optional.CrossRider O39 - APT: globalUpdateUpdateTaskMachineCore - (.globalUpdate.) -- C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job [970] =>PUP.Optional.GlobalUpdate O39 - APT: globalUpdateUpdateTaskMachineUA - (.globalUpdate.) -- C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job [974] =>PUP.Optional.GlobalUpdate O39 - APT: GPUKLMB1 - (...) -- C:\WINDOWS\Tasks\GPUKLMB1.job [366] =>PUP.Optional.FlashBeat O39 - APT: MyBrowser - (...) -- C:\WINDOWS\Tasks\MyBrowser.job [1084] O39 - APT: RegClean Pro_DEFAULT - (...) -- C:\WINDOWS\Tasks\RegClean Pro_DEFAULT.job [294] =>PUP.Optional.RegistryPowerCleaner O39 - APT: RegClean Pro_UPDATES - (...) -- C:\WINDOWS\Tasks\RegClean Pro_UPDATES.job [302] =>PUP.Optional.RegistryPowerCleaner O39 - APT: SpeedUpMyPC Maintenance - (.Uniblue Systems Limited.) -- C:\WINDOWS\Tasks\SpeedUpMyPC Maintenance.job [314] =>PUP.Optional.SpeedUpMyPC O39 - APT: SpeedUpMyPC Startup - (.Uniblue Systems Limited.) -- C:\WINDOWS\Tasks\SpeedUpMyPC Startup.job [308] =>PUP.Optional.SpeedUpMyPC O39 - APT: TDKXEPIRGITQYRAS - (.All rights reserved..) -- C:\WINDOWS\Tasks\TDKXEPIRGITQYRAS.job [378] =>Heuristic.Graftor O39 - APT: Uninstaller_SkipUac_rober - (.IObit.) -- C:\WINDOWS\Tasks\Uninstaller_SkipUac_rober.job [310] © O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6 - (.InstallMoon.) -- C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6 [6260] =>PUP.Optional.CrossRider O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7 - (.InstallMoon.) -- C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7 [6596] =>PUP.Optional.CrossRider O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-11 - (.InstallMoon.) -- C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-11 [8304] =>PUP.Optional.CrossRider O39 - APT: 1fd558bf-2f63-4070-8891-3e2e3f82401e-5 - (.InstallMoon.) -- C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-5 [5564] =>PUP.Optional.CrossRider O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater [3878] © O39 - APT: Advanced System~Protector - (.Copyright.) -- C:\WINDOWS\System32\Tasks\Advanced System~Protector [3778] =>PUP.Optional.AdvancedSystemProtector O39 - APT: Advanced System~Protector_startup - (.Copyright.) -- C:\WINDOWS\System32\Tasks\Advanced System~Protector_startup [3218] =>PUP.Optional.AdvancedSystemProtector O39 - APT: APSnotifierPP1 - (.AnyProtect.com.) -- C:\WINDOWS\System32\Tasks\APSnotifierPP1 [2876] =>PUP.Optional.AnyProtect O39 - APT: APSnotifierPP2 - (.AnyProtect.com.) -- C:\WINDOWS\System32\Tasks\APSnotifierPP2 [2874] =>PUP.Optional.AnyProtect O39 - APT: APSnotifierPP3 - (.AnyProtect.com.) -- C:\WINDOWS\System32\Tasks\APSnotifierPP3 [2874] =>PUP.Optional.AnyProtect O39 - APT: ASC8_PerformanceMonitor - (.IObit.) -- C:\WINDOWS\System32\Tasks\ASC8_PerformanceMonitor [3322] © O39 - APT: ASC8_SkipUac_rober - (.IObit.) -- C:\WINDOWS\System32\Tasks\ASC8_SkipUac_rober [2446] © O39 - APT: ASP - (.Systweak Inc.) -- C:\WINDOWS\System32\Tasks\ASP [3398] =>PUP.Optional.Systweak O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6 - (...) -- C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6 [6272] =>PUP.Optional.CrossRider O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7 - (...) -- C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7 [6608] =>PUP.Optional.CrossRider O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11 - (...) -- C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11 [8316] =>PUP.Optional.CrossRider O39 - APT: c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5 - (...) -- C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5 [5920] =>PUP.Optional.CrossRider O39 - APT: Convertor - (...) -- C:\WINDOWS\System32\Tasks\Convertor [3860] O39 - APT: crash_service - (...) -- C:\WINDOWS\System32\Tasks\crash_service [3306] =>PUP.Optional.BoBrowser O39 - APT: Driver Booster Scan - (.IObit.) -- C:\WINDOWS\System32\Tasks\Driver Booster Scan [3362] © O39 - APT: Driver Booster SkipUAC (rober) - (.IObit.) -- C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (rober) [3074] © O39 - APT: Driver Booster Update - (.IObit.) -- C:\WINDOWS\System32\Tasks\Driver Booster Update [3310] © O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-1-6 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-6 [6294] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-1-7 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-7 [6630] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-11 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-11 [8338] =>PUP.Optional.CrossRider O39 - APT: fe88b57d-f774-4a30-a287-8727f629acfa-5 - (.CinemaPlus-3.2cV11.09.) -- C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-5 [5598] =>PUP.Optional.CrossRider O39 - APT: globalUpdateUpdateTaskMachineCore - (.globalUpdate.) -- C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineCore [3812] =>PUP.Optional.GlobalUpdate O39 - APT: globalUpdateUpdateTaskMachineUA - (.globalUpdate.) -- C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineUA [4044] =>PUP.Optional.GlobalUpdate O39 - APT: GPUKLMB1 - (...) -- C:\WINDOWS\System32\Tasks\GPUKLMB1 [2932] =>PUP.Optional.FlashBeat O39 - APT: Internet Quick Access Updater - (.Copyright © 2014.) -- C:\WINDOWS\System32\Tasks\Internet Quick Access Updater [3698] =>PUP.Optional.InternetQuickAccess O39 - APT: LaunchPreSignup - (...) -- C:\WINDOWS\System32\Tasks\LaunchPreSignup [4110] =>PUP.Optional.MyPCBackup O39 - APT: MSIAfterburner - (.Copyright © 2009-2015 Alexey Nicolaychuk aka Unwinder.) -- C:\WINDOWS\System32\Tasks\MSIAfterburner [3146] O39 - APT: MyBrowser - (...) -- C:\WINDOWS\System32\Tasks\MyBrowser [4200] O39 - APT: MyPC Backup Updater - (.Copyright © 2014.) -- C:\WINDOWS\System32\Tasks\MyPC Backup Updater [3554] =>PUP.Optional.MyPCBackup O39 - APT: PostPoneInstall - (...) -- C:\WINDOWS\System32\Tasks\PostPoneInstall [4184] O39 - APT: RegClean Pro - (...) -- C:\WINDOWS\System32\Tasks\RegClean Pro [3150] =>PUP.Optional.RegistryPowerCleaner O39 - APT: RegClean Pro_DEFAULT - (...) -- C:\WINDOWS\System32\Tasks\RegClean Pro_DEFAULT [2962] =>PUP.Optional.RegistryPowerCleaner O39 - APT: RegClean Pro_UPDATES - (...) -- C:\WINDOWS\System32\Tasks\RegClean Pro_UPDATES [3118] =>PUP.Optional.RegistryPowerCleaner O39 - APT: Rocha - (...) -- C:\WINDOWS\System32\Tasks\Rocha [3728] =>PUP.Optional.Shopperz O39 - APT: RTSS - (.Copyright © 2005-2014 by Alexey Nicolaychuk aka Unwin.) -- C:\WINDOWS\System32\Tasks\RTSS [3126] O39 - APT: Run_Bobby_Browser - (...) -- C:\WINDOWS\System32\Tasks\Run_Bobby_Browser [3282] =>PUP.Optional.BoBrowser O39 - APT: SmartWeb Upgrade Trigger Task - (.SoftBrain Technologies Ltd..) -- C:\WINDOWS\System32\Tasks\SmartWeb Upgrade Trigger Task [4146] =>PUP.Optional.SmartWebSearch O39 - APT: SpeedUpMyPC Maintenance - (.Uniblue Systems Limited.) -- C:\WINDOWS\System32\Tasks\SpeedUpMyPC Maintenance [3360] =>PUP.Optional.SpeedUpMyPC O39 - APT: SpeedUpMyPC Startup - (.Uniblue Systems Limited.) -- C:\WINDOWS\System32\Tasks\SpeedUpMyPC Startup [2656] =>PUP.Optional.SpeedUpMyPC O39 - APT: SpyHunter4Startup - (.Enigma Software Group USA, LLC..) -- C:\WINDOWS\System32\Tasks\SpyHunter4Startup [3462] =>.Superfluous.SpyHunter O39 - APT: svchost - (.TZ.) -- C:\WINDOWS\System32\Tasks\svchost [3118] O39 - APT: TDKXEPIRGITQYRAS - (.All rights reserved..) -- C:\WINDOWS\System32\Tasks\TDKXEPIRGITQYRAS [3458] =>Heuristic.Graftor O39 - APT: Tnuimuni - (...) -- C:\WINDOWS\System32\Tasks\Tnuimuni [3542] =>Heuristic.PullUpdate O39 - APT: Uninstaller_SkipUac_rober - (.IObit.) -- C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_rober [2496] © O39 - APT: updateTask - (...) -- C:\WINDOWS\System32\Tasks\updateTask [3254] O39 - APT: VLCUpdate - (...) -- C:\WINDOWS\System32\Tasks\VLCUpdate [3734] O39 - APT: WinKit - (...) -- C:\WINDOWS\System32\Tasks\WinKit [3338] O39 - APT: Winsta Update - (...) -- C:\WINDOWS\System32\Tasks\Winsta Update [3392] O39 - APT: WordSurfer Auto Updater 1.10.0.19 Core - (.Word Surfer.) -- C:\WINDOWS\System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Core [4284] =>PUP.Optional.WordSurfer O39 - APT: WordSurfer Auto Updater 1.10.0.19 Pending Update - (.Word Surfer.) -- C:\WINDOWS\System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Pending Update [4314] =>PUP.Optional.WordSurfer ---\\ Software instalados (64) - 5s O42 - Logiciel: Autodesk 3ds Max 2015 - (.Autodesk.) [HKLM][64Bits] -- Autodesk 3ds Max 2015 © O42 - Logiciel: Autodesk 3ds Max 2015 SP1 - (.Autodesk.) [HKLM][64Bits] -- Autodesk 3ds Max 2015 SP1 © O42 - Logiciel: Autodesk DirectConnect 2015 64-bit - (.Autodesk.) [HKLM][64Bits] -- Autodesk DirectConnect 2015 64-bit © O42 - Logiciel: Autodesk DirectConnect 2015 64-bit Hotfix1 - (.Autodesk.) [HKLM][64Bits] -- Autodesk DirectConnect 2015 64-bit_9001 © O42 - Logiciel: Autodesk Revit Interoperability for 3ds Max 2015 - (.Autodesk.) [HKLM][64Bits] -- Autodesk Revit Interoperability for 3ds Max 2015 © O42 - Logiciel: DAEMON Tools Ultra - (.Disc Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Ultra © O42 - Logiciel: EPSON L355 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM][64Bits] -- EPSON L355 Series © O42 - Logiciel: NetBeans IDE 8.0.2 - (.NetBeans.org.) [HKLM][64Bits] -- nbi-nb-base-8.0.2.0.201411181905 © O42 - Logiciel: MyPC Backup - (.MyPC Backup.) [HKLM][64Bits] -- OLBPre =>PUP.Optional.MyPCBackup O42 - Logiciel: Autodesk Revit Interoperability for 3ds Max 2015 - (.Autodesk.) [HKLM][64Bits] -- {0BB716E0-1500-0610-0000-097DC2F354DF} © O42 - Logiciel: Java 8 Update 60 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418060F0} © O42 - Logiciel: Autodesk 3ds Max 2015 - (.Autodesk.) [HKLM][64Bits] -- {52B37EC7-D836-0410-0264-3C24BCED2010} © O42 - Logiciel: Autodesk 3ds Max 2015 Populate Data - (.Autodesk.) [HKLM][64Bits] -- {57E92DED-DC6C-41E5-B9E1-76D83BD2EABE} © O42 - Logiciel: Java SE Development Kit 8 Update 60 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {64A3A4F4-B792-11D6-A78A-00B0D0180600} © O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {8C775E70-A791-4DA8-BCC3-6AB7136F4484} © O42 - Logiciel: Autodesk Inventor Server Engine for 3ds Max 2015 - (.Autodesk.) [HKLM][64Bits] -- {9167CA34-4E48-49E3-8892-3C439739D2D3} © O42 - Logiciel: Advanced Calendar 2.0 - (.TopTools100.) [HKLM][64Bits] -- {D9BAB2C9-5236-48c3-AF02-67E799F09BBD} O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E2078C11-E9EC-BD96-037C-A3423082F2BF} © O42 - Logiciel: Advanced-System Protector - (.Advanced System Protector.) [HKLM][64Bits] -- 00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~9338DF9D_is1 =>PUP.Optional.AdvancedSystemProtector O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR © O42 - Logiciel: Adobe Flash Player 18 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI © O42 - Logiciel: Advanced SystemCare 8 - (.IObit.) [HKLM][64Bits] -- Advanced SystemCare 8_is1 © O42 - Logiciel: MSI Afterburner 4.1.1 - (.MSI Co., LTD.) [HKLM][64Bits] -- Afterburner © O42 - Logiciel: AIDA64 Extreme v5.20 - (.FinalWire Ltd..) [HKLM][64Bits] -- AIDA64 Extreme_is1 © O42 - Logiciel: AnyProtect - (.CMI Limited.) [HKLM][64Bits] -- AnyProtect =>PUP.Optional.AnyProtect O42 - Logiciel: Autodesk Application Manager - (.Autodesk.) [HKLM][64Bits] -- Autodesk Application Manager © O42 - Logiciel: CinemaPlus-3.2cV11.09 - (.CinemaPlus-3.2cV11.09.) [HKLM][64Bits] -- CinemaPlus-3.2cV11.09 =>PUP.Optional.CrossRider O42 - Logiciel: Driver Booster 2.3 - (.IObit.) [HKLM][64Bits] -- Driver Booster_is1 © O42 - Logiciel: Scratch 2 Offline Editor - (.MIT Media Lab.) [HKLM][64Bits] -- edu.media.mit.Scratch2Editor O42 - Logiciel: GoHD - (.InstallMoon.) [HKLM][64Bits] -- GoHD =>PUP.Optional.CrossRider O42 - Logiciel: Surfing Protection - (.IObit.) [HKLM][64Bits] -- IObit Surfing Protection_is1 © O42 - Logiciel: IObit Uninstaller - (.IObit.) [HKLM][64Bits] -- IObitUninstall © O42 - Logiciel: LG PC Suite - (.LG Electronics.) [HKLM][64Bits] -- LG PC Suite © O42 - Logiciel: mystartsearch uninstall - (.mystartsearch.) [HKLM][64Bits] -- mystartsearch uninstall =>PUP.Optional.StartSearch O42 - Logiciel: Origin - (.Electronic Arts, Inc..) [HKLM][64Bits] -- Origin © O42 - Logiciel: Raptr - (...) [HKLM][64Bits] -- Raptr O42 - Logiciel: RegClean-Pro - (.systweak.com.) [HKLM][64Bits] -- RegClean-Pro_is1 O42 - Logiciel: Dark Souls 2 - (...) [HKLM][64Bits] -- RGFya1NvdWxzMg==_is1 O42 - Logiciel: RivaTuner Statistics Server 6.3.0 - (.Unwinder.) [HKLM][64Bits] -- RTSS O42 - Logiciel: SmartWeb - (.SoftBrain Technologies Ltd..) [HKLM][64Bits] -- SmartWeb =>PUP.Optional.SmartWebSearch O42 - Logiciel: KMPlayer (remove only) - (.PandoraTV.) [HKLM][64Bits] -- The KMPlayer O42 - Logiciel: Wajam - (.Wajam.) [HKLM][64Bits] -- WajaInternetEn =>PUP.Optional.Wajam O42 - Logiciel: Arquivo do WinRAR - (...) [HKLM][64Bits] -- WinRAR archiver O42 - Logiciel: WordSurfer 1.10.0.19 - (.WordSurfer.) [HKLM][64Bits] -- WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer O42 - Logiciel: AMD Catalyst Control Center - (.AMD.) [HKLM][64Bits] -- WUCCCApp © O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11087D24-567D-7D88-69C6-D7A08B5F4C47} © O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {31B9D218-FED2-4C6C-B19F-7294FFC130B0} © O42 - Logiciel: Autodesk Material Library 2015 - (.Autodesk.) [HKLM][64Bits] -- {427F733F-4D6C-45BC-9324-EB743104C321} © O42 - Logiciel: LG United Mobile Drivers - (.LG Electronics.) [HKLM][64Bits] -- {4DE95ED9-0A29-4C4F-8463-35857CF9BA36} © O42 - Logiciel: Scratch 2 Offline Editor - (.MIT Media Lab.) [HKLM][64Bits] -- {55C50340-9692-5580-2451-B0C73A6788D4} O42 - Logiciel: THE WITCHER 3 WILD HUNT - (.CD PROJEKT RED.) [HKLM][64Bits] -- {5B16803D-D598-4EDA-9E8E-A3D76F625EBF} © O42 - Logiciel: Adobe Photoshop CS6 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {74EB3499-8B95-4B5C-96EB-7B342F3FD0C6} © O42 - Logiciel: Autodesk Backburner 2015 - (.Autodesk.) [HKLM][64Bits] -- {8C5F38D2-8EFE-49A4-B3F5-BF3210FED168} © O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} © O42 - Logiciel: Autodesk Material Library Medium Resolution Image Library 2015 - (.Autodesk.) [HKLM][64Bits] -- {9F6466D9-6EFC-4A10-B931-C72D1A3F1763} © O42 - Logiciel: globalupdate Helper - (.globalupdate Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>PUP.Optional.GlobalUpdate O42 - Logiciel: Autodesk Material Library Base Resolution Image Library 2015 - (.Autodesk.) [HKLM][64Bits] -- {ABE2F70B-8D94-44E9-AA04-F0DB35063D62} © O42 - Logiciel: SpyHunter - (.Enigma Software Group USA, LLC.) [HKLM][64Bits] -- {AF549236-6258-4AC6-A043-5B5B89C6EB61} =>.Superfluous.SpyHunter O42 - Logiciel: PDF Settings CS6 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {BFEAAE77-BD7F-4534-B286-9C5CB4697EB1} © O42 - Logiciel: aTube Catcher versão 3.8 - (.DsNET Corp.) [HKLM][64Bits] -- {D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1 © O42 - Logiciel: SpeedUpMyPC - (.Uniblue Systems Limited.) [HKLM][64Bits] -- {E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 =>PUP.Optional.Uniblue O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} © O42 - Logiciel: Internet Quick Access - (.Internet Quick Access.) [HKCU][64Bits] -- InternetQuickAccess =>PUP.Optional.InternetQuickAccess O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent ---\\ HKCU & HKLM Software Keys (162) - 5s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\AdwCleaner HKLM\SOFTWARE\Wow6432Node\AIM Toolbar HKLM\SOFTWARE\Wow6432Node\AppDataLow HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. HKLM\SOFTWARE\Wow6432Node\ArenaHD =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\AskPartnerNetwork =>Toolbar.AskBar HKLM\SOFTWARE\Wow6432Node\ATI HKLM\SOFTWARE\Wow6432Node\ATI Technologies HKLM\SOFTWARE\Wow6432Node\Autodesk HKLM\SOFTWARE\Wow6432Node\Avg HKLM\SOFTWARE\Wow6432Node\CD PROJEKT RED HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV11.09 =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV11.09-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\Clara =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\Conduit =>PUP.Optional.Conduit HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse HKLM\SOFTWARE\Wow6432Node\Durante HKLM\SOFTWARE\Wow6432Node\EA Games HKLM\SOFTWARE\Wow6432Node\Electronic Arts HKLM\SOFTWARE\Wow6432Node\EnigmaSoftwareGroup HKLM\SOFTWARE\Wow6432Node\EPSON HKLM\SOFTWARE\Wow6432Node\EVP HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP =>PUP.Optional.GamesDesktop HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Wow6432Node\GoHD =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\GoHD-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\HighDefAction =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\I - Cinema-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\IHProtect =>PUP.Optional.AgentODR HKLM\SOFTWARE\Wow6432Node\Iminent =>PUP.Optional.IMBouster HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\InterVideo HKLM\SOFTWARE\Wow6432Node\IObit HKLM\SOFTWARE\Wow6432Node\JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\KMPlayer HKLM\SOFTWARE\Wow6432Node\LG Electronics HKLM\SOFTWARE\Wow6432Node\LogMeInRescueCallingCard HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\MSI HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\omniboxesSoftware =>PUP.Optional.Omniboxes HKLM\SOFTWARE\Wow6432Node\Origin HKLM\SOFTWARE\Wow6432Node\Origin Games HKLM\SOFTWARE\Wow6432Node\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic HKLM\SOFTWARE\Wow6432Node\Raptr HKLM\SOFTWARE\Wow6432Node\Reg HKLM\SOFTWARE\Wow6432Node\rising HKLM\SOFTWARE\Wow6432Node\RisingRepire HKLM\SOFTWARE\Wow6432Node\SearchProtect =>PUP.Optional.SearchProtect HKLM\SOFTWARE\Wow6432Node\searchult =>PUP.Optional.Generic HKLM\SOFTWARE\Wow6432Node\shopperz100920151159 =>PUP.Optional.Shopperz HKLM\SOFTWARE\Wow6432Node\SpeedBit HKLM\SOFTWARE\Wow6432Node\SRS Labs HKLM\SOFTWARE\Wow6432Node\SupDp =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\supTab =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\supWindowsMangerProtect =>PUP.Optional.WpManager HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak HKLM\SOFTWARE\Wow6432Node\Tencent =>PUP.Optional.TencentAddressBar HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue HKLM\SOFTWARE\Wow6432Node\Unwinder HKLM\SOFTWARE\Wow6432Node\VideoLAN HKLM\SOFTWARE\Wow6432Node\WajaInternetEn HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro HKLM\SOFTWARE\Wow6432Node\WinRAR HKLM\SOFTWARE\Wow6432Node\WordShark_1.10.0.20 =>PUP.Optional.WordShark HKLM\SOFTWARE\Wow6432Node\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer HKLM\SOFTWARE\Wow6432Node\YorkNewCin =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\ZoomWebLists =>PUP.Optional.Zoom HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\Akeo Consulting HKCU\SOFTWARE\AnyProtect =>PUP.Optional.AnyProtect HKCU\SOFTWARE\AOL HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\ArenaHD =>PUP.Optional.CrossRider HKCU\SOFTWARE\AskPartnerNetwork =>Toolbar.AskBar HKCU\SOFTWARE\ATI HKCU\SOFTWARE\Autodesk HKCU\SOFTWARE\AutoHelpDesk HKCU\SOFTWARE\Baidu HKCU\SOFTWARE\BitTorrent HKCU\SOFTWARE\CD Projekt RED HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\CinemaPlus-3.2cV10.09-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\CinemaPlus-3.2cV11.09-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\Crossbrowse =>PUP.Optional.CrossBrowse HKCU\SOFTWARE\CrossBrowser =>PUP.Optional.CrossBrowser HKCU\SOFTWARE\Crystal Dynamics HKCU\SOFTWARE\DailyPcClean =>PUP.Optional.DailyPCClean HKCU\SOFTWARE\Disc Soft HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\EA Games HKCU\SOFTWARE\Electronic Arts HKCU\SOFTWARE\EPSON HKCU\SOFTWARE\FinalWire HKCU\SOFTWARE\GbPlugin HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate HKCU\SOFTWARE\GoHD-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\Google HKCU\SOFTWARE\HighDefAction =>PUP.Optional.CrossRider HKCU\SOFTWARE\HomeTab =>PUP.Optional.CertifiedToolbar HKCU\SOFTWARE\I - Cinema-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKCU\SOFTWARE\InstallPath HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\KMPlayer HKCU\SOFTWARE\Kromtech HKCU\SOFTWARE\LG Electronics HKCU\SOFTWARE\Licenses HKCU\SOFTWARE\Linkey =>PUP.Optional.LinkeySearch HKCU\SOFTWARE\LogMeInRescueCallingCard HKCU\SOFTWARE\LowRegistry HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\MSI HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\PDFConvert HKCU\SOFTWARE\perforce HKCU\SOFTWARE\PPStream HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\QyGameClient =>PUP.Optional.IQIYIVideo HKCU\SOFTWARE\Raptr HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\Reg HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SearchProtectWS =>PUP.Optional.SearchProtect HKCU\SOFTWARE\SimplyTech =>PUP.Optional.SimplyTech HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak HKCU\SOFTWARE\Tencent =>PUP.Optional.TencentAddressBar HKCU\SOFTWARE\TNT2 =>PUP.Optional.TidyNetwork HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive HKCU\SOFTWARE\Unity HKCU\SOFTWARE\Unwinder HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\VLCU HKCU\SOFTWARE\WajIEnhance =>PUP.Optional.Wajam HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\Xilisoft HKCU\SOFTWARE\YeaInstaller HKCU\SOFTWARE\YorkNewCin =>PUP.Optional.CrossRider HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\SmartWeb =>PUP.Optional.SmartWebSearch HKCU\SOFTWARE\AppDataLow\Software\Unity ---\\ Conteúdo das pastas Programs (259) - 5s O43 - CFD: 2015/09/11 10:45:40 - [] D -- C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5 =>PUP.Optional.CrossRider O43 - CFD: 2015/09/08 15:38:52 - [] D -- C:\Program Files (x86)\Adobe O43 - CFD: 2015/07/18 07:39:30 - [] D -- C:\Program Files (x86)\AMD O43 - CFD: 2015/09/11 14:28:05 - [] D -- C:\Program Files (x86)\AnyProtectEx =>PUP.Optional.AnyProtect O43 - CFD: 2015/09/11 14:24:42 - [] D -- C:\Program Files (x86)\ASP =>PUP.Optional.AdvancedSystemProtector O43 - CFD: 2015/09/08 14:23:23 - [] D -- C:\Program Files (x86)\Autodesk O43 - CFD: 2015/09/10 20:32:20 - [] D -- C:\Program Files (x86)\baidu O43 - CFD: 2015/07/30 12:52:16 - [] D -- C:\Program Files (x86)\CalendarTool O43 - CFD: 2015/09/11 08:49:33 - [] D -- C:\Program Files (x86)\CinemaPlus-3.2cV11.09 =>PUP.Optional.CrossRider O43 - CFD: 2015/09/11 14:25:31 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 2015/09/10 20:49:29 - [] D -- C:\Program Files (x86)\Convertor O43 - CFD: 2015/07/18 08:51:08 - [] D -- C:\Program Files (x86)\Disc Soft O43 - CFD: 2015/08/27 07:18:28 - [] D -- C:\Program Files (x86)\DsNET Corp O43 - CFD: 2015/07/29 09:31:42 - [0] D -- C:\Program Files (x86)\dzrepack games O43 - CFD: 2015/09/11 08:48:29 - [] D -- C:\Program Files (x86)\Enigma Software Group =>.Superfluous.SpyHunter O43 - CFD: 2015/07/20 06:21:52 - [] D -- C:\Program Files (x86)\FinalWire O43 - CFD: 2015/08/27 13:46:02 - [] D -- C:\Program Files (x86)\GbPlugin O43 - CFD: 2015/09/11 08:49:00 - [] D -- C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate O43 - CFD: 2015/09/11 14:25:40 - [] D -- C:\Program Files (x86)\GoHD =>PUP.Optional.CrossRider O43 - CFD: 2015/09/10 20:32:20 - [0] D -- C:\Program Files (x86)\I - Cinema =>PUP.Optional.CrossRider O43 - CFD: 2015/08/27 14:07:33 - [0] D -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 2015/08/23 06:54:02 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 2015/07/20 06:24:58 - [] D -- C:\Program Files (x86)\IObit O43 - CFD: 2015/08/16 07:23:50 - [] D -- C:\Program Files (x86)\LG Electronics O43 - CFD: 2015/09/03 15:06:42 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 2015/08/23 02:03:25 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 2015/09/06 17:55:05 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 2015/09/03 15:06:29 - [] D -- C:\Program Files (x86)\MSECache O43 - CFD: 2015/09/09 19:37:28 - [] D -- C:\Program Files (x86)\MSI Afterburner O43 - CFD: 2015/09/10 19:33:08 - [] D -- C:\Program Files (x86)\MyBrowser O43 - CFD: 2015/09/11 14:24:41 - [] D -- C:\Program Files (x86)\OLBPre =>PUP.Optional.MyPCBackup O43 - CFD: 2015/09/02 07:25:42 - [] D -- C:\Program Files (x86)\Origin O43 - CFD: 2015/07/18 07:40:41 - [] D -- C:\Program Files (x86)\Origin Games O43 - CFD: 2015/09/10 20:26:44 - [0] D -- C:\Program Files (x86)\predm =>PUP.Optional.Downware O43 - CFD: 2015/07/29 09:05:37 - [] D -- C:\Program Files (x86)\Raptr O43 - CFD: 2015/09/11 14:24:10 - [] D -- C:\Program Files (x86)\RCP O43 - CFD: 2015/09/06 17:55:05 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 2015/09/10 20:35:16 - [] D -- C:\Program Files (x86)\Rising O43 - CFD: 2015/07/25 09:57:57 - [] D -- C:\Program Files (x86)\RivaTuner Statistics Server O43 - CFD: 2015/08/27 14:07:34 - [0] D -- C:\Program Files (x86)\Samsung O43 - CFD: 2015/09/05 17:22:36 - [] D -- C:\Program Files (x86)\Scratch 2 O43 - CFD: 2015/09/11 14:23:31 - [] D -- C:\Program Files (x86)\SFK =>PUP.Optional.MyWebSearch O43 - CFD: 2015/09/10 19:56:04 - [] D -- C:\Program Files (x86)\Tencent =>PUP.Optional.TencentAddressBar O43 - CFD: 2015/09/06 18:32:13 - [] D -- C:\Program Files (x86)\Tribo Gamer O43 - CFD: 2015/09/11 14:25:07 - [] D -- C:\Program Files (x86)\Uniblue =>PUP.Optional.Uniblue O43 - CFD: 2015/09/10 20:57:02 - [0] D -- C:\Program Files (x86)\UPCleaner O43 - CFD: 2015/09/10 20:47:03 - [0] D -- C:\Program Files (x86)\VideoLAN O43 - CFD: 2015/08/23 06:54:02 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 2015/08/23 06:54:02 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 2015/08/23 06:54:02 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 2015/08/23 02:03:32 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 2015/08/23 02:03:25 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 2015/08/23 06:54:02 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 2015/08/23 02:03:32 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 2015/08/23 02:03:25 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 2015/08/23 02:03:25 - [] SD -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 2015/07/20 06:22:45 - [] D -- C:\Program Files (x86)\WinRAR O43 - CFD: 2015/09/10 20:49:31 - [] D -- C:\Program Files (x86)\Winsta O43 - CFD: 2015/09/11 14:22:01 - [] D -- C:\Program Files (x86)\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer O43 - CFD: 2015/08/23 02:03:33 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/08/23 06:57:36 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/08/23 06:57:36 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8 O43 - CFD: 2015/09/11 14:24:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System~Protector =>PUP.Optional.AdvancedSystemProtector O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher O43 - CFD: 2015/09/08 14:26:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk O43 - CFD: 2015/09/08 14:23:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk 3ds Max 2015 O43 - CFD: 2015/09/08 14:23:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk Backburner 2015 O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Ultra O43 - CFD: 2015/09/11 08:09:34 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop Search O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2 O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire O43 - CFD: 2015/09/11 09:17:48 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP =>PUP.Optional.GamesDesktop O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller O43 - CFD: 2015/08/31 01:43:15 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 2015/08/31 01:43:15 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG PC Suite O43 - CFD: 2015/08/23 02:03:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/31 01:44:48 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBeans O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin O43 - CFD: 2015/09/11 14:24:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro =>PUP.Optional.RegistryPowerCleaner O43 - CFD: 2015/08/27 14:07:33 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung O43 - CFD: 2015/08/23 02:03:33 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 2015/08/23 02:03:33 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2015/08/23 06:57:34 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THE WITCHER 3 WILD HUNT O43 - CFD: 2015/09/06 18:32:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer O43 - CFD: 2015/09/11 14:25:09 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue =>PUP.Optional.Uniblue O43 - CFD: 2015/09/11 14:23:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEn O43 - CFD: 2015/08/27 23:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 2015/09/10 19:21:35 - [] D -- C:\ProgramData\28341ff220e0446c9fff27c4493d622e O43 - CFD: 2015/09/10 20:47:54 - [] D -- C:\ProgramData\4WdsManPro4 =>PUP.Optional.WdsManPro O43 - CFD: 2015/09/10 19:52:12 - [] D -- C:\ProgramData\7WdsManPro7 =>PUP.Optional.WdsManPro O43 - CFD: 2015/09/10 19:56:47 - [0] D -- C:\ProgramData\adb O43 - CFD: 2015/09/08 15:39:41 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2015/08/23 02:34:45 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2015/07/30 08:43:24 - [] D -- C:\ProgramData\ATI O43 - CFD: 2015/09/08 14:25:55 - [] D -- C:\ProgramData\Autodesk O43 - CFD: 2015/09/11 14:06:12 - [] D -- C:\ProgramData\AVAST Software O43 - CFD: 2015/09/11 10:55:21 - [] HD -- C:\ProgramData\Common Files O43 - CFD: 2015/08/23 02:03:25 - [0] D -- C:\ProgramData\Comms O43 - CFD: 2015/07/18 01:16:24 - [0] SHD -- C:\ProgramData\Dados de Aplicativos O43 - CFD: 2015/07/18 08:49:27 - [] D -- C:\ProgramData\DAEMON Tools Ultra O43 - CFD: 2015/08/23 02:34:45 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2015/07/18 01:16:24 - [0] SHD -- C:\ProgramData\Documentos O43 - CFD: 2015/08/23 02:34:45 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2015/07/18 07:30:47 - [] D -- C:\ProgramData\Electronic Arts O43 - CFD: 2015/08/03 17:40:18 - [] D -- C:\ProgramData\EPSON O43 - CFD: 2015/09/11 14:23:15 - [0] D -- C:\ProgramData\eWdsManProe =>PUP.Optional.WdsManPro O43 - CFD: 2015/08/27 13:36:49 - [] D -- C:\ProgramData\GAS Tecnologia O43 - CFD: 2015/09/05 02:16:48 - [] D -- C:\ProgramData\GbPlugin O43 - CFD: 2015/09/08 09:32:53 - [0] D -- C:\ProgramData\IDM O43 - CFD: 2015/07/18 19:49:44 - [] D -- C:\ProgramData\IHProtectUpDate =>PUP.Optional.AgentODR O43 - CFD: 2015/07/20 06:31:55 - [] D -- C:\ProgramData\IObit O43 - CFD: 2015/09/10 20:21:59 - [0] D -- C:\ProgramData\IQIYI Video =>PUP.Optional.IQIYIVideo O43 - CFD: 2015/09/10 19:23:05 - [] D -- C:\ProgramData\LocalStorage O43 - CFD: 2015/07/18 01:16:24 - [0] SHD -- C:\ProgramData\Menu Iniciar O43 - CFD: 2015/09/11 11:00:16 - [] D -- C:\ProgramData\MFAData O43 - CFD: 2015/08/27 23:54:30 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/07/18 01:20:16 - [] D -- C:\ProgramData\Microsoft OneDrive O43 - CFD: 2015/07/18 01:16:24 - [0] SHD -- C:\ProgramData\Modelos O43 - CFD: 2015/09/11 14:22:27 - [] D -- C:\ProgramData\MWdsManProM =>PUP.Optional.WdsManPro O43 - CFD: 2015/08/31 01:43:05 - [] D -- C:\ProgramData\Oracle O43 - CFD: 2015/09/09 06:44:56 - [] D -- C:\ProgramData\Origin O43 - CFD: 2015/09/11 09:18:21 - [] D -- C:\ProgramData\OWdsManProO =>PUP.Optional.WdsManPro O43 - CFD: 2015/09/08 14:10:15 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 2015/09/06 16:37:34 - [] D -- C:\ProgramData\ProductData O43 - CFD: 2015/09/10 19:33:41 - [] D -- C:\ProgramData\pWdsManProp =>PUP.Optional.WdsManPro O43 - CFD: 2015/09/08 15:39:41 - [] D -- C:\ProgramData\regid.1986-12.com.adobe O43 - CFD: 2015/08/23 06:57:34 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 2015/09/10 20:32:31 - [] D -- C:\ProgramData\Rising O43 - CFD: 2015/08/15 13:39:02 - [] D -- C:\ProgramData\Samsung O43 - CFD: 2015/09/10 19:21:36 - [] D -- C:\ProgramData\Service1291 O43 - CFD: 2015/08/23 02:03:25 - [0] D -- C:\ProgramData\SoftwareDistribution O43 - CFD: 2015/08/23 02:34:45 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2015/08/08 13:03:46 - [] D -- C:\ProgramData\Steam O43 - CFD: 2015/09/11 14:24:42 - [] D -- C:\ProgramData\Systweak =>PUP.Optional.Systweak O43 - CFD: 2015/08/23 02:34:45 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/09/10 20:22:25 - [] D -- C:\ProgramData\Tencent =>PUP.Optional.TencentAddressBar O43 - CFD: 2015/09/10 20:49:50 - [] D -- C:\ProgramData\Tnuimuni O43 - CFD: 2015/08/15 15:41:44 - [] D -- C:\ProgramData\ToolsUpdatePlatform O43 - CFD: 2015/09/10 20:47:16 - [] D -- C:\ProgramData\tWdsManProt =>PUP.Optional.WdsManPro O43 - CFD: 2015/09/10 20:37:29 - [0] D -- C:\ProgramData\TXQMPC O43 - CFD: 2015/09/11 08:45:25 - [] D -- C:\ProgramData\UGCojBbwir O43 - CFD: 2015/08/23 02:36:00 - [] D -- C:\ProgramData\USOPrivate O43 - CFD: 2015/08/23 02:35:59 - [] D -- C:\ProgramData\USOShared O43 - CFD: 2015/08/19 03:48:50 - [] D -- C:\ProgramData\WindowsMangerProtect =>PUP.Optional.WpManager O43 - CFD: 2015/07/18 08:39:23 - [0] D -- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} O43 - CFD: 2015/09/08 15:37:31 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 2015/08/31 20:35:49 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR O43 - CFD: 2015/09/08 14:25:45 - [] D -- C:\Program Files (x86)\Common Files\Autodesk Shared O43 - CFD: 2015/07/18 07:48:39 - [] HD -- C:\Program Files (x86)\Common Files\EAInstaller O43 - CFD: 2015/07/18 08:39:19 - [] D -- C:\Program Files (x86)\Common Files\IObit O43 - CFD: 2015/08/31 01:43:22 - [] D -- C:\Program Files (x86)\Common Files\Java O43 - CFD: 2015/09/03 15:06:43 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 2015/08/23 02:03:32 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 2015/08/23 06:54:02 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 2015/09/10 19:56:07 - [] D -- C:\Program Files (x86)\Common Files\Tencent =>PUP.Optional.TencentAddressBar O43 - CFD: 2015/09/11 08:46:56 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard O43 - CFD: 2015/09/08 16:06:56 - [] D -- C:\Users\rober\AppData\Roaming\Adobe O43 - CFD: 2015/07/18 19:26:05 - [] D -- C:\Users\rober\AppData\Roaming\AMD O43 - CFD: 2015/09/10 20:28:13 - [] SHD -- C:\Users\rober\AppData\Roaming\AnyProtectEx =>PUP.Optional.AnyProtect O43 - CFD: 2015/07/18 08:39:23 - [] D -- C:\Users\rober\AppData\Roaming\Apple Computer O43 - CFD: 2015/07/18 07:24:44 - [] D -- C:\Users\rober\AppData\Roaming\ATI O43 - CFD: 2015/09/08 14:13:29 - [] D -- C:\Users\rober\AppData\Roaming\Autodesk O43 - CFD: 2015/07/30 12:52:19 - [] D -- C:\Users\rober\AppData\Roaming\CalendarTool O43 - CFD: 2015/09/10 20:44:25 - [] D -- C:\Users\rober\AppData\Roaming\cpuminer O43 - CFD: 2015/07/29 09:32:29 - [] D -- C:\Users\rober\AppData\Roaming\DAEMON Tools Ultra O43 - CFD: 2015/08/08 13:05:18 - [] D -- C:\Users\rober\AppData\Roaming\DarkSoulsII O43 - CFD: 2015/09/11 08:12:33 - [0] D -- C:\Users\rober\AppData\Roaming\DMCache O43 - CFD: 2015/08/31 20:36:00 - [] D -- C:\Users\rober\AppData\Roaming\edu.media.mit.Scratch2Editor O43 - CFD: 2015/07/20 06:25:04 - [] D -- C:\Users\rober\AppData\Roaming\IObit O43 - CFD: 2015/09/10 19:16:29 - [] D -- C:\Users\rober\AppData\Roaming\IQIYI Video =>PUP.Optional.IQIYIVideo O43 - CFD: 2015/08/16 07:27:26 - [] D -- C:\Users\rober\AppData\Roaming\LG Electronics O43 - CFD: 2015/07/18 07:41:55 - [] D -- C:\Users\rober\AppData\Roaming\library_dir O43 - CFD: 2015/07/18 08:01:21 - [] D -- C:\Users\rober\AppData\Roaming\Macromedia O43 - CFD: 2015/09/11 08:48:30 - [] SD -- C:\Users\rober\AppData\Roaming\Microsoft O43 - CFD: 2015/09/11 14:23:14 - [] D -- C:\Users\rober\AppData\Roaming\mystartsearch =>PUP.Optional.StartSearch O43 - CFD: 2015/08/31 06:32:12 - [] D -- C:\Users\rober\AppData\Roaming\NetBeans O43 - CFD: 2015/07/18 19:37:27 - [] D -- C:\Users\rober\AppData\Roaming\NVIDIA 3D Vision Video Player O43 - CFD: 2015/09/10 20:49:59 - [] D -- C:\Users\rober\AppData\Roaming\Opera Software O43 - CFD: 2015/07/18 07:47:59 - [] D -- C:\Users\rober\AppData\Roaming\Origin O43 - CFD: 2015/09/10 19:33:05 - [] D -- C:\Users\rober\AppData\Roaming\ortmp O43 - CFD: 2015/09/10 20:49:29 - [] D -- C:\Users\rober\AppData\Roaming\PDFConvert O43 - CFD: 2015/09/10 19:16:00 - [] D -- C:\Users\rober\AppData\Roaming\ppslog O43 - CFD: 2015/07/20 02:42:31 - [] D -- C:\Users\rober\AppData\Roaming\ProductData O43 - CFD: 2015/09/11 13:52:09 - [] D -- C:\Users\rober\AppData\Roaming\Raptr O43 - CFD: 2015/07/18 07:57:17 - [] D -- C:\Users\rober\AppData\Roaming\RHEng =>PUP.Optional.Conduit O43 - CFD: 2015/08/27 14:07:34 - [] D -- C:\Users\rober\AppData\Roaming\Samsung O43 - CFD: 2015/09/08 16:06:56 - [] D -- C:\Users\rober\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 O43 - CFD: 2015/08/22 23:07:35 - [] D -- C:\Users\rober\AppData\Roaming\Steam O43 - CFD: 2015/08/31 01:43:16 - [] D -- C:\Users\rober\AppData\Roaming\Sun O43 - CFD: 2015/09/11 14:24:43 - [] D -- C:\Users\rober\AppData\Roaming\systweak =>PUP.Optional.Systweak O43 - CFD: 2015/09/10 19:56:26 - [] D -- C:\Users\rober\AppData\Roaming\Tencent =>PUP.Optional.TencentAddressBar O43 - CFD: 2015/08/22 23:14:51 - [] D -- C:\Users\rober\AppData\Roaming\Trine3 O43 - CFD: 2015/09/11 14:25:07 - [] D -- C:\Users\rober\AppData\Roaming\Uniblue =>PUP.Optional.Uniblue O43 - CFD: 2015/09/11 14:21:28 - [] D -- C:\Users\rober\AppData\Roaming\uTorrent O43 - CFD: 2015/09/10 20:04:02 - [] D -- C:\Users\rober\AppData\Roaming\WB_CFG O43 - CFD: 2015/09/11 08:45:25 - [0] D -- C:\Users\rober\AppData\Roaming\wenguanjia O43 - CFD: 2015/07/20 06:22:58 - [] D -- C:\Users\rober\AppData\Roaming\WinRAR O43 - CFD: 2015/07/18 19:26:04 - [] D -- C:\Users\rober\AppData\Roaming\Xilisoft O43 - CFD: 2015/09/11 14:38:06 - [] D -- C:\Users\rober\AppData\Roaming\ZHP O43 - CFD: 2015/09/11 13:53:22 - [] D -- C:\Users\rober\AppData\Local\ActiveSync O43 - CFD: 2015/09/08 16:04:10 - [] D -- C:\Users\rober\AppData\Local\Adobe O43 - CFD: 2015/07/18 07:24:44 - [] D -- C:\Users\rober\AppData\Local\ATI O43 - CFD: 2015/09/08 14:10:20 - [] D -- C:\Users\rober\AppData\Local\Autodesk O43 - CFD: 2015/09/11 10:55:21 - [] D -- C:\Users\rober\AppData\Local\Avg2015 O43 - CFD: 2015/09/11 14:26:46 - [] D -- C:\Users\rober\AppData\Local\Chromium O43 - CFD: 2015/09/02 19:52:49 - [] D -- C:\Users\rober\AppData\Local\Comms O43 - CFD: 2015/08/27 23:51:23 - [0] SHD -- C:\Users\rober\AppData\Local\Dados de Aplicativos O43 - CFD: 2015/09/10 20:50:15 - [] D -- C:\Users\rober\AppData\Local\DesktopSearch =>PUP.Optional.DesktopSearch O43 - CFD: 2015/09/09 16:54:36 - [0] D -- C:\Users\rober\AppData\Local\Diagnostics O43 - CFD: 2015/07/18 08:51:15 - [] D -- C:\Users\rober\AppData\Local\Disc_Soft_Ltd O43 - CFD: 2015/09/05 02:13:37 - [] D -- C:\Users\rober\AppData\Local\EA Games O43 - CFD: 2015/08/26 16:14:37 - [0] D -- C:\Users\rober\AppData\Local\ElevatedDiagnostics O43 - CFD: 2015/09/10 19:21:04 - [] D -- C:\Users\rober\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate O43 - CFD: 2015/09/11 13:54:40 - [] D -- C:\Users\rober\AppData\Local\gmsd_br_005010084 O43 - CFD: 2015/09/10 19:21:27 - [] D -- C:\Users\rober\AppData\Local\gmsd_us_005010074 O43 - CFD: 2015/08/27 23:51:23 - [0] SHD -- C:\Users\rober\AppData\Local\Histórico O43 - CFD: 2015/08/16 07:24:08 - [] D -- C:\Users\rober\AppData\Local\LG Electronics O43 - CFD: 2015/09/10 20:35:51 - [] D -- C:\Users\rober\AppData\Local\macasoft O43 - CFD: 2015/09/11 10:55:21 - [] D -- C:\Users\rober\AppData\Local\MFAData O43 - CFD: 2015/09/08 14:15:36 - [] D -- C:\Users\rober\AppData\Local\Microsoft O43 - CFD: 2015/07/20 02:51:27 - [] D -- C:\Users\rober\AppData\Local\MicrosoftEdge O43 - CFD: 2015/08/31 06:32:09 - [] D -- C:\Users\rober\AppData\Local\NetBeans O43 - CFD: 2015/09/10 20:50:00 - [] D -- C:\Users\rober\AppData\Local\Opera Software O43 - CFD: 2015/07/19 07:25:14 - [] D -- C:\Users\rober\AppData\Local\Origin O43 - CFD: 2015/09/11 08:24:55 - [] D -- C:\Users\rober\AppData\Local\Packages O43 - CFD: 2015/07/18 07:07:29 - [0] D -- C:\Users\rober\AppData\Local\PackageStaging O43 - CFD: 2015/07/18 19:50:06 - [0] D -- C:\Users\rober\AppData\Local\PeerDistRepub O43 - CFD: 2015/07/18 08:38:55 - [] D -- C:\Users\rober\AppData\Local\Programs O43 - CFD: 2015/07/18 01:19:06 - [] D -- C:\Users\rober\AppData\Local\Publishers O43 - CFD: 2015/09/11 14:22:06 - [] D -- C:\Users\rober\AppData\Local\SmartWeb =>PUP.Optional.SmartWebSearch O43 - CFD: 2015/09/10 19:33:25 - [] D -- C:\Users\rober\AppData\Local\SysassistByHotWheel =>PUP.Optional.Generic O43 - CFD: 2015/09/10 20:51:35 - [] D -- C:\Users\rober\AppData\Local\Systweak =>PUP.Optional.Systweak O43 - CFD: 2015/09/11 14:37:53 - [] D -- C:\Users\rober\AppData\Local\Temp O43 - CFD: 2015/09/10 19:33:07 - [0] D -- C:\Users\rober\AppData\Local\Tempfolder O43 - CFD: 2015/08/27 23:51:23 - [0] SHD -- C:\Users\rober\AppData\Local\Temporary Internet Files O43 - CFD: 2015/07/18 01:18:50 - [] D -- C:\Users\rober\AppData\Local\TileDataLayer O43 - CFD: 2015/09/10 20:23:44 - [0] D -- C:\Users\rober\AppData\Local\Unity O43 - CFD: 2015/08/27 13:43:48 - [] D -- C:\Users\rober\AppData\Local\VirtualStore O43 - CFD: 2015/08/23 02:03:33 - [] RD -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/08/27 23:51:32 - [] RD -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/09/11 13:45:21 - [] RD -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/09/11 10:20:29 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup =>PUP.Optional.AnyProtect O43 - CFD: 2015/09/06 19:22:42 - [0] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dead Space 3 [Lossless repack by R.G. Catalyst] O43 - CFD: 2015/09/11 14:26:45 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Quick Access =>PUP.Optional.InternetQuickAccess O43 - CFD: 2015/08/23 02:03:33 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/27 23:51:32 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner O43 - CFD: 2015/08/27 23:51:32 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server O43 - CFD: 2015/09/11 08:48:30 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter =>.Superfluous.SpyHunter O43 - CFD: 2015/09/11 14:23:27 - [] RD -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2015/08/23 02:03:33 - [] RD -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2015/08/27 23:51:32 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer O43 - CFD: 2015/08/23 02:04:12 - [] RSD -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell O43 - CFD: 2015/08/27 23:51:32 - [] D -- C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ Últimos arquivos criados no Windows Prefetcher (49) - 15s O45 - LFCP:[MD5.0896219D1AA9E6991F50F0E8B75226C2] 2015/09/11 14:24:44 A -- C:\WINDOWS\Prefetch\ADVANCEDSYSTEMPROTECTOR.EXE-E30B6CE6.pf =>PUP.Optional.AdvancedSystemProtector O45 - LFCP:[MD5.757A672822068862A5FC57BE877019E6] 2015/09/11 14:28:11 A -- C:\WINDOWS\Prefetch\ANYPROTECT.EXE-1996592C.pf =>PUP.Optional.AnyProtect O45 - LFCP:[MD5.028541D45D23F5E33238C402A11C5922] 2015/09/10 20:21:37 A -- C:\WINDOWS\Prefetch\BOBROWSER.EXE-7BB7AB57.pf =>PUP.Optional.BoBrowser O45 - LFCP:[MD5.7EEEDA318A85D9C95743F9CE5640DF18] 2015/09/10 19:20:00 A -- C:\WINDOWS\Prefetch\CLARAUPDATER.EXE-875FA871.pf =>PUP.Optional.SupTab O45 - LFCP:[MD5.ED41650B38908A504C935DE05ECF924A] 2015/09/10 20:44:40 A -- C:\WINDOWS\Prefetch\DESKTOPSEARCH_SOFT_PARTNER.EX-539B1EEB.pf =>PUP.Optional.DesktopSearch O45 - LFCP:[MD5.431F7139A3E4752631814C7A2F47E0C5] 2015/09/10 19:21:55 A -- C:\WINDOWS\Prefetch\FLASHBEAT.EXE-7F5ED19D.pf =>PUP.Optional.FlashBeat O45 - LFCP:[MD5.B905754408539782378198D184C9F4EF] 2015/09/11 14:30:01 A -- C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-35F6B904.pf =>PUP.Optional.GlobalUpdate O45 - LFCP:[MD5.E0EBA932558062B072F079CDFEEFD20B] 2015/09/10 20:48:57 A -- C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-8AF1FB91.pf =>PUP.Optional.GlobalUpdate O45 - LFCP:[MD5.61307367EAB8B0824287B9C15B04F0E7] 2015/09/10 20:52:01 A -- C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-9034CA88.pf =>PUP.Optional.GlobalUpdate O45 - LFCP:[MD5.2C0BB4AD1A02B50EB755E1EFDA700C18] 2015/09/11 14:25:30 A -- C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-A5FFDA83.pf =>PUP.Optional.GlobalUpdate O45 - LFCP:[MD5.E8BEC7A6ADE79A5C7C02FBEF0F96AEC2] 2015/09/10 19:35:04 A -- C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-DC37E952.pf =>PUP.Optional.GlobalUpdate O45 - LFCP:[MD5.8B926767DFD8373CE3A6D3500D3B1A30] 2015/09/11 14:30:00 A -- C:\WINDOWS\Prefetch\GLOBALUPDATECRASHHANDLER.EXE-68CB7B8C.pf =>PUP.Optional.GlobalUpdate O45 - LFCP:[MD5.9E8C72C01427BD32ECE70EE946D58208] 2015/09/11 14:23:37 A -- C:\WINDOWS\Prefetch\OLBPRE.EXE-C6385661.pf =>PUP.Optional.MyPCBackup O45 - LFCP:[MD5.14BC14C886A27367561128EC620CE2EB] 2015/09/10 20:49:42 A -- C:\WINDOWS\Prefetch\PREDM.EXE-1FCA533C.pf =>PUP.Optional.Downware O45 - LFCP:[MD5.BD81EE6316D1A75B78C259B0823B546F] 2015/09/10 20:40:46 A -- C:\WINDOWS\Prefetch\PREDM.EXE-4366456F.pf =>PUP.Optional.Downware O45 - LFCP:[MD5.8BECE7791D39B98055C39B4137F46C71] 2015/09/10 20:25:45 A -- C:\WINDOWS\Prefetch\PREDM.TMP-19039B47.pf =>PUP.Optional.Downware O45 - LFCP:[MD5.F7B94F5A77D8DF7066EF978E9347D2E0] 2015/09/10 20:40:46 A -- C:\WINDOWS\Prefetch\PREDM.TMP-626FDBE5.pf =>PUP.Optional.Downware O45 - LFCP:[MD5.99769BE7270B1EBE4285A3831766E762] 2015/09/10 20:49:42 A -- C:\WINDOWS\Prefetch\PREDM.TMP-DC27314D.pf =>PUP.Optional.Downware O45 - LFCP:[MD5.CDEF30578362C607CAF45B1A1DB6C04C] 2015/09/11 14:22:18 A -- C:\WINDOWS\Prefetch\SMARTWEBAPP.EXE-C15B5E8C.pf =>PUP.Optional.SmartWebSearch O45 - LFCP:[MD5.D084E7ABF82EB7B186115403ACED0169] 2015/09/11 14:22:16 A -- C:\WINDOWS\Prefetch\SMARTWEBHELPER.EXE-D9CBB7C7.pf =>PUP.Optional.SmartWebSearch O45 - LFCP:[MD5.0B9C00230F16948E995D12392DC84B28] 2015/09/11 14:25:08 A -- C:\WINDOWS\Prefetch\SPEEDUPMYPC-STANDALONE-SETUP.-2617F7D5.pf =>PUP.Optional.SpeedUpMyPC O45 - LFCP:[MD5.8CE883290B23FC4C8D28DBB9456E79DF] 2015/09/11 14:25:12 A -- C:\WINDOWS\Prefetch\SPEEDUPMYPC-STANDALONE-SETUP.-477C310D.pf =>PUP.Optional.SpeedUpMyPC O45 - LFCP:[MD5.4957B3B275A3C4C9F7F873810DF7016F] 2015/09/11 14:25:21 A -- C:\WINDOWS\Prefetch\SPEEDUPMYPC.EXE-E9FC9CD7.pf =>PUP.Optional.SpeedUpMyPC O45 - LFCP:[MD5.E81B28B56345E7DD83B9A81344B35AD9] 2015/09/11 08:26:24 A -- C:\WINDOWS\Prefetch\SPYHUNTER-INSTALLER.EXE-3C8E00EF.pf =>.Superfluous.SpyHunter O45 - LFCP:[MD5.3650B4FAD4AC907AC76D8613DA4512FE] 2015/09/11 08:52:04 A -- C:\WINDOWS\Prefetch\SPYHUNTER.4.3.32-PATCH.EXE-D2A57466.pf =>.Superfluous.SpyHunter O45 - LFCP:[MD5.8BF25D69A15D102ABB7C1FB6633C233C] 2015/09/11 08:53:00 A -- C:\WINDOWS\Prefetch\SPYHUNTER.4.3.32-PATCH.EXE-D75FD585.pf =>.Superfluous.SpyHunter O45 - LFCP:[MD5.D984E04447384DD62EE9689170A5891B] 2015/09/11 08:53:14 A -- C:\WINDOWS\Prefetch\SPYHUNTER4.EXE-6272DFA2.pf =>.Superfluous.SpyHunter O45 - LFCP:[MD5.D4EDE42F557A2291FC02C87A705E9D34] 2015/09/11 08:28:19 A -- C:\WINDOWS\Prefetch\SPYHUNTER4.EXE-7BD5E907.pf =>.Superfluous.SpyHunter O45 - LFCP:[MD5.4090B13F5D32F236DA290570357D0E8D] 2015/09/11 14:24:23 A -- C:\WINDOWS\Prefetch\SYSTWEAKASP.EXE-DA3A3BD5.pf =>PUP.Optional.Systweak O45 - LFCP:[MD5.02A64E6F6A932B33F71DEBE84CEF04CF] 2015/09/10 20:50:51 A -- C:\WINDOWS\Prefetch\SYSTWEAKASP.TMP-C781DD29.pf =>PUP.Optional.Systweak O45 - LFCP:[MD5.32ADED9C391CE95D1E17618EF2EA01C7] 2015/09/11 14:24:23 A -- C:\WINDOWS\Prefetch\SYSTWEAKASP.TMP-EC0918C3.pf =>PUP.Optional.Systweak O45 - LFCP:[MD5.A996942B7EF5F66459E390E1952B931B] 2015/09/11 07:42:00 A -- C:\WINDOWS\Prefetch\TENCENTDL.EXE-D4BCC9C9.pf =>PUP.Optional.TencentAddressBar O45 - LFCP:[MD5.3D6E4D9D9759E1C553760D7A798F9B9A] 2015/09/11 14:25:49 A -- C:\WINDOWS\Prefetch\WAJAM.EXE-35E970A1.pf =>PUP.Optional.Wajam O45 - LFCP:[MD5.07CF836E2A95A2C515D8C63FB256B518] 2015/09/11 14:34:02 A -- C:\WINDOWS\Prefetch\WAJAM_64.EXE-39BDE776.pf =>PUP.Optional.Wajam O45 - LFCP:[MD5.7CA4CBDC5CC5C9E30E6F77D6DBF21C03] 2015/09/10 20:50:01 A -- C:\WINDOWS\Prefetch\WAJAM_DOWNLOAD_V2.EXE-275BA10E.pf =>PUP.Optional.Wajam O45 - LFCP:[MD5.55AAD8132B8DC5485699825C8D750A16] 2015/09/11 14:23:46 A -- C:\WINDOWS\Prefetch\WAJAM_DOWNLOAD_V2.EXE-BDAA0249.pf =>PUP.Optional.Wajam O45 - LFCP:[MD5.D3866573AF8569F6358131B77A957D4A] 2015/09/10 20:46:25 A -- C:\WINDOWS\Prefetch\WDSMANPRO.EXE-093D3707.pf =>PUP.Optional.WdsManPro O45 - LFCP:[MD5.190EB719031E57D696DF05B947336115] 2015/09/11 14:22:27 A -- C:\WINDOWS\Prefetch\WDSMANPRO.EXE-0F82C291.pf =>PUP.Optional.WdsManPro O45 - LFCP:[MD5.DA82437D6C0EB3A5F342E60A91ABEFE2] 2015/09/10 19:32:50 A -- C:\WINDOWS\Prefetch\WDSMANPRO.EXE-55F73D9F.pf =>PUP.Optional.WdsManPro O45 - LFCP:[MD5.F8FA128C19BE57473C82864E3F92EBAF] 2015/09/10 20:47:55 A -- C:\WINDOWS\Prefetch\WDSMANPRO.EXE-6F0D6BC7.pf =>PUP.Optional.WdsManPro O45 - LFCP:[MD5.55BC42D04FDD2508ADC643A8023221FF] 2015/09/10 19:52:13 A -- C:\WINDOWS\Prefetch\WDSMANPRO.EXE-B581E6D5.pf =>PUP.Optional.WdsManPro O45 - LFCP:[MD5.F3527CE4BDBFA867F71ADA8F4C08A5E3] 2015/09/11 09:17:30 A -- C:\WINDOWS\Prefetch\WDSMANPRO.EXE-E925BF45.pf =>PUP.Optional.WdsManPro O45 - LFCP:[MD5.35AB39436C1F6C98D8C49090B5B47C8C] 2015/09/11 14:22:01 A -- C:\WINDOWS\Prefetch\WORDSURFERAUTOUPDATECLIENT.EX-4E78B08A.pf =>PUP.Optional.WordSurfer O45 - LFCP:[MD5.49C07A104CCE6DD8A5CBCB85A0E874D2] 2015/09/10 19:32:39 A -- C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-587E245A.pf =>PUP.Optional.WpManager O45 - LFCP:[MD5.C7CD4D4854D0E3F648A3F9B656B8EDCF] 2015/09/10 20:46:15 A -- C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-5AC96A75.pf =>PUP.Optional.WpManager O45 - LFCP:[MD5.FD2FBC45314FABF1CAA157F50E974CB6] 2015/09/11 14:23:15 A -- C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-BC734F0B.pf =>PUP.Optional.WpManager O45 - LFCP:[MD5.28DB8719EAA163907D86CD70617A893F] 2015/09/11 09:17:20 A -- C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-C1A4000D.pf =>PUP.Optional.WpManager O45 - LFCP:[MD5.82D76DCE44325600A1F84CF49978EC96] 2015/09/11 14:22:27 A -- C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-D18D8379.pf =>PUP.Optional.WpManager O45 - LFCP:[MD5.AECDDBC24DD601B1DBCAAA6D2A540C70] 2015/09/10 19:52:13 A -- C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-E6D5D969.pf =>PUP.Optional.WpManager ---\\ Lista dos drivers do sistema (60) - 1s O58 - SDL:2015/08/23 01:50:48 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107496] © O58 - SDL:2015/08/23 01:50:48 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135592] © O58 - SDL:2015/07/15 23:09:00 A . (.Advanced Micro Devices - AMD ACP Binaries.) -- C:\WINDOWS\System32\drivers\amdacpksd.sys [297672] © O58 - SDL:2015/06/03 10:35:36 A . (.Advanced Micro Devices, Inc. - AMD Audio Bus Lower Filter.) -- C:\WINDOWS\System32\drivers\amdkmafd.sys [31992] © O58 - SDL:2015/08/23 01:50:48 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [84952] © O58 - SDL:2015/08/23 01:50:48 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259560] © O58 - SDL:2015/08/23 01:50:48 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27112] © O58 - SDL:2015/08/23 01:50:48 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [133592] © O58 - SDL:2015/07/21 20:42:04 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\AtihdWT6.sys [102912] © O58 - SDL:2015/07/15 23:06:36 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\atikmdag.sys [21622272] © O58 - SDL:2015/07/15 22:13:26 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\WINDOWS\System32\drivers\atikmpag.sys [665088] © O58 - SDL:2015/08/23 01:50:48 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn.sys [17656] © O58 - SDL:2015/08/23 01:50:48 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] © O58 - SDL:2015/09/10 19:35:59 A . (.Copyright (c) 2012 - .) -- C:\WINDOWS\System32\drivers\bsdriver.sys [34720] =>PUP.Optional.Shopperz O58 - SDL:2015/08/23 01:50:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531432] © O58 - SDL:2015/08/20 11:46:12 A . (.Windows (R) Win 7 DDK provider - Cherimoya Ltd.) -- C:\WINDOWS\System32\drivers\cherimoya.sys [56736] © O58 - SDL:2015/07/18 08:49:55 A . (.Disc Soft Ltd - DAEMON Tools Ultra Virtual SCSI Bus Driver.) -- C:\WINDOWS\System32\drivers\dtultrascsibus.sys [30264] © O58 - SDL:2015/07/18 08:50:09 A . (.Disc Soft Ltd - DAEMON Tools Ultra Virtual USB Bus Driver.) -- C:\WINDOWS\System32\drivers\dtultrausbbus.sys [47160] © O58 - SDL:2015/08/23 01:50:48 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3438552] © O58 - SDL:2015/07/18 01:20:17 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [56344] © O58 - SDL:2015/09/11 14:06:13 A . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\System32\drivers\hmozbdjr.sys [436624] © O58 - SDL:2015/08/23 01:50:49 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64488] © O58 - SDL:2015/08/23 01:50:31 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] © O58 - SDL:2015/08/23 01:50:31 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608] © O58 - SDL:2015/08/23 01:50:49 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673256] © O58 - SDL:2015/08/23 01:50:49 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412136] © O58 - SDL:2015/08/23 01:50:55 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [426456] © O58 - SDL:2015/06/11 23:00:58 N . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [197616] © O58 - SDL:2015/01/21 13:55:54 A . (.LG Electronics Inc. - LGE AndroidNet Driver.) -- C:\WINDOWS\System32\drivers\lgandnetbus64.sys [20992] O58 - SDL:2015/01/26 09:22:42 A . (.LG Electronics Inc. - LGE AndroidNet Driver.) -- C:\WINDOWS\System32\drivers\lgandnetdiag64.sys [30720] O58 - SDL:2015/01/26 09:23:56 A . (.LG Electronics Inc. - LGE AndroidNet Driver.) -- C:\WINDOWS\System32\drivers\lgandnetmodem64.sys [37376] O58 - SDL:2015/08/23 01:50:49 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [110552] © O58 - SDL:2015/08/23 01:50:53 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104936] © O58 - SDL:2015/08/23 01:50:55 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [100824] © O58 - SDL:2015/08/23 01:50:55 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [84440] © O58 - SDL:2015/08/23 01:50:55 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59880] © O58 - SDL:2015/08/23 01:50:55 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575976] © O58 - SDL:2015/08/23 01:50:55 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [707032] © O58 - SDL:2015/08/23 01:50:56 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63976] © O58 - SDL:2015/08/23 01:50:55 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [77784] © O58 - SDL:2015/08/23 01:50:57 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [152024] © O58 - SDL:2015/08/23 01:50:57 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [167896] © O58 - SDL:2015/08/23 01:50:57 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [59864] © O58 - SDL:2015/08/23 01:50:57 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58856] © O58 - SDL:2015/09/02 17:10:18 A . (.PhraseProfessor - PP WFP Driver x64.) -- C:\WINDOWS\System32\drivers\ppfd_vw_1_10_0_24.sys [57744] =>PUP.Optional.Generic O58 - SDL:2015/07/30 08:17:08 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [886528] © O58 - SDL:2015/08/04 13:55:14 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [4514008] © O58 - SDL:2015/08/23 01:50:57 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [46552] © O58 - SDL:2015/08/23 01:50:57 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [83416] © O58 - SDL:2015/07/22 08:50:55 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [42696] © O58 - SDL:2015/08/23 01:50:57 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [32728] © O58 - SDL:2015/09/10 19:56:05 A . (.Tencent Technology(Shenzhen) Company Limited - TAOKernel.) -- C:\WINDOWS\System32\drivers\TAOKernel64.sys [274232] O58 - SDL:2015/09/10 19:56:05 A . (.电脑管家 - 电脑管家-驱动模块.) -- C:\WINDOWS\System32\drivers\TFsFltX64.sys [87864] O58 - SDL:2015/09/11 14:06:32 A . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\System32\drivers\udyomisf.sys [436624] © O58 - SDL:2015/08/23 01:50:57 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166888] © O58 - SDL:2015/08/23 01:50:57 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [307160] © O58 - SDL:2015/08/23 01:50:55 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [28632] © O58 - SDL:2015/08/23 01:50:55 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [60888] © O58 - SDL:2015/06/15 19:28:50 A . (.Word Surfer - Word Surfer WFP Driver x64.) -- C:\WINDOWS\System32\drivers\wsafd_1_10_0_19.sys [57728] =>PUP.Optional.WordSurfer O58 - SDL:2015/07/06 16:11:34 A . (.WS - WS WFP Driver x64.) -- C:\WINDOWS\System32\drivers\wsfd_vw_1_10_0_20.sys [57728] =>PUP.Optional.Generic ---\\ Últimos ficheiros alterados ou criados (Utilizador) (61) - 4s O61 - LFC: 2015/09/08 09:30:01 A . (..) -- C:\Users\rober\Downloads\3dsMax_2016_EXT1.exe [207645928] O61 - LFC: 2015/09/05 02:17:30 A . (.Tribo Gamer Brasil®.) -- C:\Users\rober\Downloads\dead_space3_br.exe [1141142] O61 - LFC: 2015/09/11 14:27:57 A . (..) -- C:\Users\rober\Downloads\JRT.exe [0] O61 - LFC: 2015/09/11 08:26:13 A . (.Enigma Software Group USA, LLC..) -- C:\Users\rober\Downloads\SpyHunter-Installer.exe [3237248] =>.Superfluous.SpyHunter O61 - LFC: 2015/09/10 18:59:11 A . (..) -- C:\Users\rober\Downloads\Programs\Extractor__8680_i1639950123_il7.exe [1074352] O61 - LFC: 2015/09/11 14:24:22 A . (..) -- C:\Users\rober\AppData\Roaming\systweak\regclean pro\Version 6.1\backup3.bin [677] =>PUP.Optional.RegistryPowerCleaner O61 - LFC: 2015/09/11 14:24:22 A . (..) -- C:\Users\rober\AppData\Roaming\systweak\regclean pro\Version 6.1\backup4.bin [549] =>PUP.Optional.RegistryPowerCleaner O61 - LFC: 2015/09/11 14:24:22 A . (..) -- C:\Users\rober\AppData\Roaming\systweak\regclean pro\Version 6.1\backup6.bin [600] =>PUP.Optional.RegistryPowerCleaner O61 - LFC: 2015/09/10 17:45:26 A . (..) -- C:\Users\rober\AppData\Roaming\Raptr\data\raptrguest9pjcxzp1\config\certificates\x509\tls_peers\xmpp-server2.raptr.com [1217] O61 - LFC: 2015/09/11 13:52:07 A . (..) -- C:\Users\rober\AppData\Roaming\Raptr\data\raptrguest9pjcxzp1\config\certificates\x509\tls_peers\xmpp-server4.raptr.com [1217] O61 - LFC: 2015/09/11 13:45:54 A . (..) -- C:\Users\rober\AppData\Roaming\Raptr\data\raptrguest9pjcxzp1\config\certificates\x509\tls_peers\xmpp-server5.raptr.com [1217] O61 - LFC: 2015/09/07 23:41:09 A . (..) -- C:\Users\rober\AppData\Roaming\Raptr\data\raptrguest9pjcxzp1\config\certificates\x509\tls_peers\xmpp-server6.raptr.com [1217] O61 - LFC: 2015/09/09 16:18:36 A . (..) -- C:\Users\rober\AppData\Roaming\Raptr\data\raptrguest9pjcxzp1\config\certificates\x509\tls_peers\xmpp-server7.raptr.com [1217] O61 - LFC: 2015/09/09 05:58:55 A . (..) -- C:\Users\rober\AppData\Roaming\Raptr\data\raptrguest9pjcxzp1\config\certificates\x509\tls_peers\xmpp-server8.raptr.com [1217] O61 - LFC: 2015/09/10 06:02:20 A . (..) -- C:\Users\rober\AppData\Roaming\ortmp\uninstaller.exe [233408] O61 - LFC: 2015/09/08 05:55:32 A . (.TODO: .) -- C:\Users\rober\AppData\Roaming\mystartsearch\UninstallManager.exe [375296] =>PUP.Optional.StartSearch O61 - LFC: 2015/09/11 08:48:30 RA . (..) -- C:\Users\rober\AppData\Roaming\Microsoft\Installer\{AF549236-6258-4AC6-A043-5B5B89C6EB61}\IconCF33A0CE.exe [110080] O61 - LFC: 2015/09/11 08:48:30 RA . (..) -- C:\Users\rober\AppData\Roaming\Microsoft\Installer\{AF549236-6258-4AC6-A043-5B5B89C6EB61}\IconD7F16134.exe [110080] O61 - LFC: 2015/09/11 08:48:30 RA . (..) -- C:\Users\rober\AppData\Roaming\Microsoft\Installer\{AF549236-6258-4AC6-A043-5B5B89C6EB61}\IconF7A21AF7.exe [110080] O61 - LFC: 2015/09/10 19:17:40 A . (.爱奇艺.) -- C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe [314984] =>PUP.Optional.IQIYIVideo O61 - LFC: 2015/09/10 19:20:14 A . (.爱奇艺.) -- C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\QyUpdate\IQIYIsetup_update_201506041.exe [7801192] =>PUP.Optional.IQIYIVideo O61 - LFC: 2015/09/10 19:19:09 A . (.爱奇艺.) -- C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\GpUpdate\GeePlayerSetup_update20150907.exe [15885000] =>PUP.Optional.IQIYIVideo O61 - LFC: 2015/09/10 19:22:11 A . (..) -- C:\Users\rober\AppData\Roaming\cpuminer\sgminer\darkcoin-modTahitigw128l4ku0.bin [2223140] O61 - LFC: 2015/09/08 16:12:18 A . (..) -- C:\Users\rober\AppData\Roaming\AMD\GLCache\5b29effe650b9c07_21.bin [16828] O61 - LFC: 2015/09/08 16:12:13 A . (..) -- C:\Users\rober\AppData\Roaming\AMD\GLCache\b169ddc631f65d92_21.bin [24701] O61 - LFC: 2015/09/11 15:15:20 A . (..) -- C:\Users\rober\AppData\Local\Systweak\Advanced System Protector\aspcontexthelper64.dll [86344] =>PUP.Optional.AdvancedSystemProtector O61 - LFC: 2015/09/11 14:22:06 A . (.SoftBrain Technologies Ltd..) -- C:\Users\rober\AppData\Local\SmartWeb\__u.exe [172673] =>PUP.Optional.SmartWebSearch O61 - LFC: 2015/09/05 09:06:08 A . (..) -- C:\Users\rober\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Data.bin [1048576] O61 - LFC: 2015/09/05 09:06:08 A . (..) -- C:\Users\rober\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Header.bin [9640] O61 - LFC: 2015/09/10 20:42:59 A . (..) -- C:\Users\rober\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_150_0_Data.bin [10192040] O61 - LFC: 2015/09/11 08:55:36 A . (..) -- C:\Users\rober\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_150_0_Header.bin [14632] O61 - LFC: 2015/09/11 14:32:27 A . (..) -- C:\Users\rober\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192] O61 - LFC: 2015/09/11 13:53:21 A . (..) -- C:\Users\rober\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635775775560160451.bin [101377] O61 - LFC: 2015/09/11 14:21:47 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\e0ZSW2P0[1].exe [165898] O61 - LFC: 2015/09/11 14:25:11 A . (.InstallMoon.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\setup[1].exe [12143936] =>PUP.Optional.CrossRider O61 - LFC: 2015/09/11 14:22:05 A . (.SoftBrain Technologies Ltd..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\SmartWebInstaller[1].exe [759544] =>PUP.Optional.SmartWebSearch O61 - LFC: 2015/09/11 14:25:49 A . (.Copyright 2013.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\Validate[1].exe [61981] O61 - LFC: 2015/09/11 14:23:36 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\WWE_1.51.1.16[1].exe [3723504] O61 - LFC: 2015/09/11 14:25:51 A . (.CMI Limited.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\ORDLA5PN\AnyProtectSetup[1].exe [613255] =>PUP.Optional.AnyProtect O61 - LFC: 2015/09/11 14:24:08 A . (.systweak.com.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\ORDLA5PN\rcpsetup_17970[1].exe [4445480] O61 - LFC: 2015/09/11 14:25:03 A . (.Uniblue Systems Limited.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\ORDLA5PN\SpeedUpMyPC-standalone-setup[1].exe [19136280] =>PUP.Optional.SpeedUpMyPC O61 - LFC: 2015/09/11 14:26:40 A . (.AnyProtect.com.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\AnyProtect[1].exe [6434816] =>PUP.Optional.AnyProtect O61 - LFC: 2015/09/11 09:18:02 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\FinalInstaller_dotnet4[1].exe [3030016] O61 - LFC: 2015/09/11 09:28:40 A . (.GAS Tecnologia.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\GBPCEFwr[1].exe [822320] O61 - LFC: 2015/09/11 14:22:19 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\setup_362[1].exe [254464] O61 - LFC: 2015/09/11 14:23:16 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\VuuPC_VO2_8907[1].exe [228492] =>PUP.Optional.VuuPC O61 - LFC: 2015/09/11 14:22:15 A . (.WillLink.net.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\cmi_mystartsearch[1].exe [338040] =>PUP.Optional.StartSearch O61 - LFC: 2015/09/11 14:21:46 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\cmmdWriter[1].exe [40746] O61 - LFC: 2015/09/11 08:45:43 A . (.4.2.0.4054ZoomWebLists.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\offer_7948[1].exe [162354] O61 - LFC: 2015/09/11 14:23:13 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\policyname[1].exe [55197] O61 - LFC: 2015/09/11 14:22:08 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\SearchUpdater[1].exe [124154] O61 - LFC: 2015/09/11 08:48:36 A . (.CinemaPlus-3.2cV11.09.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\setup[1].exe [13928392] O61 - LFC: 2015/09/11 09:17:24 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\setup_gmsd_br[1].exe [5791384] O61 - LFC: 2015/09/11 14:21:50 A . (.Word Surfer.) -- C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\wordsurfer-setup-1.10.0.19[1].exe [1172712] =>PUP.Optional.WordSurfer O61 - LFC: 2015/09/11 09:28:30 A . (..) -- C:\Users\rober\AppData\Local\Microsoft\Internet Explorer\UrlBlock\urlblock_635775620914039931.bin [101593] O61 - LFC: 2015/09/08 02:45:44 A . (..) -- C:\Users\rober\AppData\Local\macasoft\ntsvc.exe [121728] O61 - LFC: 2015/09/10 10:05:22 A . (..) -- C:\Users\rober\AppData\Local\gmsd_br_005010084\upgmsd_br_005010084.exe [3315344] O61 - LFC: 2015/09/11 09:21:04 A . (..) -- C:\Users\rober\AppData\Local\gmsd_br_005010084\Download\myoffergroup_br4.exe [3690840] O61 - LFC: 2015/09/11 14:26:40 A . (.IMALI - N.I. MEDIA LTD.) -- C:\Users\rober\AppData\Local\Chromium\Application\45.0.2433.0\Installer\setup.exe [933376] O61 - LFC: 2015/09/11 14:28:59 A . (.Copyright © 2014.) -- C:\Users\rober\AppData\Local\Chromium\Application\45.0.2433.0\Installer\updater\updater.exe [541696] O61 - LFC: 2015/09/11 13:51:54 A . (..) -- C:\Users\rober\AppData\Local\ATI\ACE\Manifest.Bin [30042] ---\\ Associações Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe © O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos.) -- C:\Windows\System32\eventvwr.exe © O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe © O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe © O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\Windows\regedit.exe © O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Menu de inicialização Internet (4) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.ex http://www.mystartsearch.com/ =>PUP.Optional.StartSearch O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe © ---\\ Pesquisa de infeção nos navegadores da Internet (5) - 0s O69 - SBI: SearchScopes [HKCU] OldSearch - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - (e) - http://www.omniboxes.com/ =>PUP.Optional.Omniboxes O69 - SBI: SearchScopes [HKCU] {72B54334-44D5-4816-BC0B-D71973F728D0} - (Yahoo) - http://br.search.yahoo.com/ O69 - SBI: SearchScopes [HKCU] {E733165D-CBCF-4FDA-883E-ADEF965B476C} - (Google) - http://www.omniboxes.com/ =>PUP.Optional.Omniboxes ---\\ Listagem dos serviços iniciados pelo Svchost (42) - 0s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\WINDOWS\System32\certprop.dll [192000] © O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\WINDOWS\System32\certprop.dll [192000] © O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\WINDOWS\system32\srvsvc.dll [284160] © O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\WINDOWS\System32\gpsvc.dll [1336320] © O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\WINDOWS\System32\ikeext.dll [948224] © O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\WINDOWS\System32\iphlpsvc.dll [953344] © O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\WINDOWS\system32\seclogon.dll [31232] © O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\WINDOWS\System32\appinfo.dll [92672] © O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] © O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\WINDOWS\System32\eapsvc.dll [112640] © O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\WINDOWS\system32\schedsvc.dll [1008128] © O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [225792] © O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\WINDOWS\System32\browser.dll [134656] © O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [323072] © O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho.) -- C:\Windows\System32\SessEnv.dll [372736] © O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\WINDOWS\System32\wercplsupport.dll [95744] © O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [2025472] © O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [757760] © O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\WINDOWS\system32\themeservice.dll [58880] © O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [921600] © O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL do Serviço de Gerenciamento do Windows.) -- C:\Windows\System32\Windows.Internal.Management.dll [268800] © O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Serviço de Geolocalização.) -- C:\Windows\System32\lfsvc.dll [27136] © O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acess.) -- C:\WINDOWS\System32\rasauto.dll [106496] © O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\WINDOWS\System32\rasmans.dll [681472] © O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [496128] © O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) -- C:\WINDOWS\System32\sens.dll [72704] © O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\WINDOWS\System32\ipnathlp.dll [453632] © O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft® Windows.) -- C:\Windows\System32\tapisrv.dll [311808] © O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\system32\wuaueng.dll [2240512] © O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) -- C:\WINDOWS\System32\qmgr.dll [1100800] © O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [598016] © O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [63488] © O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1133056] © O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1024000] © O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Atualizar Sessão do Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [352256] © O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\system32\dcpsvc.dll [196096] © O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\system32\RDXService.dll [1001984] © O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\WINDOWS\System32\bdesvc.dll [359936] © O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Serviço de Configuração de Rede.) -- C:\WINDOWS\System32\NetSetupSvc.dll [187392] © O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [233472] © O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede.) -- C:\WINDOWS\System32\ncasvc.dll [167424] © O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação do software.) -- C:\Windows\System32\appmgmts.dll [200192] © ---\\ Lista das exceções do FireWall (FirewallRules) (19) - 1s O87 - FAEL: "{E539C7C3-183C-4E88-8DAA-73C724845B37}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{00904544-6227-47BD-ADF5-735DEF21CAF5}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{CEC8DD68-3D19-439F-BDB4-125A0404B57F}" [Out-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{882370AF-DB45-4689-8D69-E78B71EC9B99}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{DC3F5FC0-2C43-4AAC-8BF0-F08BE4377220}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{22FD7298-AEF7-4BF2-9902-A415EA8C61F5}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{BA298B00-9C5B-4D01-8F61-6E3270C5B812}" [Out-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{E3DC4F78-7D92-49CD-BFF8-B6EEA1DA5DDC}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\rober\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{7D1765A8-F373-49A6-9EEC-5AC174E2E2A7}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe O87 - FAEL: "{9F1607A8-3AE1-4889-9B82-531077E3B96A}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe O87 - FAEL: "{ACD00CF3-69DA-485A-9A3E-AC94940EABB0}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺升级模块.) -- C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\GpUpdate.exe =>PUP.Optional.IQIYIVideo O87 - FAEL: "{336E4448-A0F6-40CC-BB46-5D2E9CC5D0CD}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺万能播放器.) -- C:\IQIYI Video\GeePlayer\GeePlayer.exe =>PUP.Optional.IQIYIVideo O87 - FAEL: "{938CA71F-52E8-45BB-8978-B0B1E9F3BEFC}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺升级模块.) -- C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe =>PUP.Optional.IQIYIVideo O87 - FAEL: "{8CC21AF2-3E80-4DDA-902E-D69F70C42681}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺PPS影音.) -- C:\IQIYI Video\LStyle\QyClient.exe =>PUP.Optional.IQIYIVideo O87 - FAEL: "{04723DD1-B594-4DF2-B853-91E75530E7DE}" [In-None-P17-TRUE] .(.爱奇艺公司 - 爱奇艺PPS影音 网页播放组件.) -- C:\IQIYI Video\LStyle\QyWebPlayer.exe =>PUP.Optional.IQIYIVideo O87 - FAEL: "{687CF3F7-3A98-44F3-B0F5-806B86EE8B1A}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺视频播放器.) -- C:\IQIYI Video\LStyle\QyPlayer.exe =>PUP.Optional.IQIYIVideo O87 - FAEL: "{398E37E7-6E34-45D0-A67B-AD12B6F62502}" [In-None-P17-TRUE] .(.Tencent - 腾讯高速下载引擎.) -- C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe =>PUP.Optional.TencentAddressBar O87 - FAEL: "{B2AD1444-9F56-4BAE-96C9-9723140FAC42}" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe =>PUP.Optional.TencentAddressBar O87 - FAEL: "{132AF449-3F65-441C-BD34-384CEE78D3C6}" [In-None-P17-TRUE] .(.IMALI - N.I. MEDIA LTD - Internet Quick Access.) -- C:\Users\rober\AppData\Local\Chromium\Application\chrome.exe ---\\ Listagem dos códigos dos software (1) - 1s O90 - PUC: "93BAD29AC2E44034A96BCB446EB8552E" . (.globalupdate Helper.) =>PUP.Optional.GlobalUpdate ---\\ Serviços não Microsoft (SR=Executados, SS=Parados) (22) - 12s SR - Auto [2015/07/30 00:40:18] [ 1129864] Autodesk Application Manager Service (AdAppMgrSvc) . (.Autodesk Inc..) - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe SS - Demand [2015/09/11 14:27:49] [ 268976] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe © SR - Auto [2015/04/03 15:42:26] [ 814880] Advanced SystemCare Service 8 (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe © SR - Auto [2015/07/15 22:17:14] [ 246784] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe © SR - Auto [2015/09/10 18:01:50] [ 1383936] Presentation Default (bebymoju) . (...) - C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\knsr701C.tmpfs =>PUP.Optional.CrossRider SS - Demand [2015/06/10 06:20:54] [ 1345368] Disc Soft Ultra Bus Service (Disc Soft Ultra Bus Service) . (.Disc Soft Ltd.) - C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe © SS - Demand [2015/09/08 14:15:34] [ 1357104] FlexNet Licensing Service 64 (FlexNet Licensing Service 64) . (.Flexera Software LLC.) - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe © SR - Auto [2014/11/03 02:47:40] [ 555320] Gbp Service (GbpSv) . (.GAS Tecnologia.) - C:\Program Files (x86)\GbPlugin\GbpSv.exe SS - Auto [2015/09/11 14:25:20] [ 68608] globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate.) - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe =>PUP.Optional.GlobalUpdate SS - Demand [2015/09/11 14:25:20] [ 68608] globalUpdate Update Service (globalUpdatem) (globalUpdatem) . (.globalUpdate.) - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe =>PUP.Optional.GlobalUpdate SR - Auto [2015/09/10 19:21:22] [ 203776] CD Feature (gyvixodu) . (...) - C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\hnslBAAA.tmp =>PUP.Optional.CrossRider SR - Auto [2015/09/10 19:21:15] [ 181760] Disk Low-res (lehicewu) . (...) - C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\jnsp9E08.tmp =>PUP.Optional.CrossRider SR - Auto [2015/07/29 09:00:46] [ 2909472] LiveUpdate (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe © SS - Demand [2011/09/15 01:19:54] [ 86016] mental ray Satellite for Autodesk 3ds Max 2015 64-bit (mi-raysat_3dsmax2015_64) . (...) - C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe SS - Demand [2015/09/02 07:25:02] [ 2057736] Origin Client Service (Origin Client Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginClientService.exe © SS - Auto [2014/01/09 07:17:38] [ 770432] SpyHunter 4 Service (SpyHunter 4 Service) . (.Enigma Software Group USA, LLC..) - C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe =>.Superfluous.SpyHunter SR - Auto [2015/09/11 14:23:16] [ 450048] SSFK (SSFK) . (.TODO: <公司名>.) - C:\Program Files (x86)\SFK\SSFK.exe =>PUP.Optional.MyWebSearch SS - Demand [2010/02/19 13:37:14] [ 517096] (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe © SR - Auto [2015/07/21 03:37:46] [ 149432] The Calendar Service (TheCalendarService) . (.Copyright (C) 2015.) - C:\Program Files (x86)\CalendarTool\2.0.0.10764\CalendarServ.exe SR - Auto [2015/09/10 11:26:26] [ 2137088] WajaInternetEn Monitor (WajaInternetEn Monitor) . (.Copyright (C) 2014.) - C:\Program Files\WajaInternetEn\wajam_64.exe =>PUP.Optional.Wajam SR - Disabled [2015/09/11 09:17:20] [ 451720] WdsManPro Service (WdsManPro) . (.DTools LIMITED.) - C:\ProgramData\OWdsManProO\WdsManPro.exe =>PUP.Optional.WpManager ---\\ Claves Tracing (2) - 1s HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASAPI32 =>PUP.Optional.WordSurfer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASMANCS =>PUP.Optional.WordSurfer ---\\ Scâner Aditional (306) - 0s C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\knsr701C.tmpfs =>PUP.Optional.CrossRider C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\hnslBAAA.tmp =>PUP.Optional.CrossRider C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5\jnsp9E08.tmp =>PUP.Optional.CrossRider C:\ProgramData\OWdsManProO\WdsManPro.exe =>PUP.Optional.WdsManPro C:\Users\rober\AppData\Local\SmartWeb\SmartWebHelper.exe =>PUP.Optional.SmartWebSearch C:\Users\rober\AppData\Local\SmartWeb\SmartWebApp.exe =>PUP.Optional.SmartWebSearch C:\Program Files (x86)\OLBPre\OLBPre.exe =>PUP.Optional.MyPCBackup C:\Program Files\WajaInternetEn\wajam_64.exe =>PUP.Optional.Wajam c:\program files\wajainterneten\wajam.exe =>PUP.Optional.Wajam C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6.exe =>PUP.Optional.CrossRider C:\IQIYI Video\LStyle\npWebPlayer.dll =>PUP.Optional.IQIYIVideo C:\IQIYI Video\LStyle\npclient.dll =>PUP.Optional.IQIYIVideo C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll =>PUP.Optional.GlobalUpdate HKLM\SYSTEM\CurrentControlSet\Services\bebymoju =>PUP.Optional.CrossRider HKLM\SYSTEM\CurrentControlSet\Services\globalUpdate =>PUP.Optional.GlobalUpdate C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe =>PUP.Optional.GlobalUpdate HKLM\SYSTEM\CurrentControlSet\Services\gyvixodu =>PUP.Optional.CrossRider HKLM\SYSTEM\CurrentControlSet\Services\lehicewu =>PUP.Optional.CrossRider HKLM\SYSTEM\CurrentControlSet\Services\SpyHunter 4 Service =>.Superfluous.SpyHunter C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe =>.Superfluous.SpyHunter HKLM\SYSTEM\CurrentControlSet\Services\SSFK =>PUP.Optional.MyWebSearch C:\Program Files (x86)\SFK\SSFK.exe =>PUP.Optional.MyWebSearch HKLM\SYSTEM\CurrentControlSet\Services\WajaInternetEn Monitor =>PUP.Optional.Wajam C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7.exe =>PUP.Optional.CrossRider C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-11.exe =>PUP.Optional.CrossRider C:\Program Files (x86)\GoHD\1fd558bf-2f63-4070-8891-3e2e3f82401e-5.exe =>PUP.Optional.CrossRider C:\Program Files (x86)\ASP\AspManager.exe =>PUP.Optional.AdvancedSystemProtector C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe =>PUP.Optional.AdvancedSystemProtector C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe =>PUP.Optional.AnyProtect C:\Program Files (x86)\RCP\systweakasp.exe =>PUP.Optional.Systweak C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-1-6.exe =>PUP.Optional.CrossRider C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-1-7.exe =>PUP.Optional.CrossRider C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-11.exe =>PUP.Optional.CrossRider C:\Program Files (x86)\CinemaPlus-3.2cV11.09\fe88b57d-f774-4a30-a287-8727f629acfa-5.exe =>PUP.Optional.CrossRider C:\Users\rober\AppData\Local\Chromium\Application\45.0.2433.0\Installer\updater\updater.exe =>PUP.Optional.InternetQuickAccess C:\Program Files (x86)\OLBPre\updater\updater.exe =>PUP.Optional.MyPCBackup C:\Program Files (x86)\RCP\RegCleanPro.exe =>PUP.Optional.RegistryPowerCleaner C:\Program Files (x86)\Enigma Software Group\SpyHunter\Spyhunter4.exe =>.Superfluous.SpyHunter C:\ProgramData\Service1291 =>Heuristic.Graftor C:\ProgramData\Service1291\Service1291.exe =>Heuristic.Graftor C:\Program Files (x86)\WordSurfer_1.10.0.19\Update\WordSurferAutoUpdateClient.exe =>PUP.Optional.WordSurfer C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-11.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-5.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\APSnotifierPP1.job =>PUP.Optional.AnyProtect C:\WINDOWS\Tasks\APSnotifierPP2.job =>PUP.Optional.AnyProtect C:\WINDOWS\Tasks\APSnotifierPP3.job =>PUP.Optional.AnyProtect C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-6.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-7.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-11.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-5.job =>PUP.Optional.CrossRider C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job =>PUP.Optional.GlobalUpdate C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job =>PUP.Optional.GlobalUpdate C:\WINDOWS\Tasks\GPUKLMB1.job =>PUP.Optional.FlashBeat C:\WINDOWS\Tasks\RegClean Pro_DEFAULT.job =>PUP.Optional.RegistryPowerCleaner C:\WINDOWS\Tasks\RegClean Pro_UPDATES.job =>PUP.Optional.RegistryPowerCleaner C:\WINDOWS\Tasks\SpeedUpMyPC Maintenance.job =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\Tasks\SpeedUpMyPC Startup.job =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\Tasks\TDKXEPIRGITQYRAS.job =>Heuristic.Graftor C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-6 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-1-7 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-11 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\1fd558bf-2f63-4070-8891-3e2e3f82401e-5 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\Advanced System~Protector =>PUP.Optional.AdvancedSystemProtector C:\WINDOWS\System32\Tasks\Advanced System~Protector_startup =>PUP.Optional.AdvancedSystemProtector C:\WINDOWS\System32\Tasks\APSnotifierPP1 =>PUP.Optional.AnyProtect C:\WINDOWS\System32\Tasks\APSnotifierPP2 =>PUP.Optional.AnyProtect C:\WINDOWS\System32\Tasks\APSnotifierPP3 =>PUP.Optional.AnyProtect C:\WINDOWS\System32\Tasks\ASP =>PUP.Optional.Systweak C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-6 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-1-7 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-11 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\crash_service =>PUP.Optional.BoBrowser C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-6 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-1-7 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-11 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\fe88b57d-f774-4a30-a287-8727f629acfa-5 =>PUP.Optional.CrossRider C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineCore =>PUP.Optional.GlobalUpdate C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineUA =>PUP.Optional.GlobalUpdate C:\WINDOWS\System32\Tasks\GPUKLMB1 =>PUP.Optional.FlashBeat C:\WINDOWS\System32\Tasks\Internet Quick Access Updater =>PUP.Optional.InternetQuickAccess C:\WINDOWS\System32\Tasks\LaunchPreSignup =>PUP.Optional.MyPCBackup C:\WINDOWS\System32\Tasks\MyPC Backup Updater =>PUP.Optional.MyPCBackup C:\WINDOWS\System32\Tasks\RegClean Pro =>PUP.Optional.RegistryPowerCleaner C:\WINDOWS\System32\Tasks\RegClean Pro_DEFAULT =>PUP.Optional.RegistryPowerCleaner C:\WINDOWS\System32\Tasks\RegClean Pro_UPDATES =>PUP.Optional.RegistryPowerCleaner C:\WINDOWS\System32\Tasks\Rocha =>PUP.Optional.Shopperz C:\WINDOWS\System32\Tasks\Run_Bobby_Browser =>PUP.Optional.BoBrowser C:\WINDOWS\System32\Tasks\SmartWeb Upgrade Trigger Task =>PUP.Optional.SmartWebSearch C:\WINDOWS\System32\Tasks\SpeedUpMyPC Maintenance =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\System32\Tasks\SpeedUpMyPC Startup =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\System32\Tasks\SpyHunter4Startup =>.Superfluous.SpyHunter C:\WINDOWS\System32\Tasks\TDKXEPIRGITQYRAS =>Heuristic.Graftor C:\WINDOWS\System32\Tasks\Tnuimuni =>Heuristic.PullUpdate C:\WINDOWS\System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Core =>PUP.Optional.WordSurfer C:\WINDOWS\System32\Tasks\WordSurfer Auto Updater 1.10.0.19 Pending Update =>PUP.Optional.WordSurfer HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre =>PUP.Optional.MyPCBackup HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~9338DF9D_is1 =>PUP.Optional.AdvancedSystemProtector HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AnyProtect =>PUP.Optional.AnyProtect HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV11.09 =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GoHD =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall =>PUP.Optional.StartSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb =>PUP.Optional.SmartWebSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WajaInternetEn =>PUP.Optional.Wajam HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AF549236-6258-4AC6-A043-5B5B89C6EB61} =>.Superfluous.SpyHunter HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 =>PUP.Optional.Uniblue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetQuickAccess =>PUP.Optional.InternetQuickAccess HKLM\SOFTWARE\Wow6432Node\ArenaHD =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\AskPartnerNetwork =>Toolbar.AskBar HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV11.09 =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV11.09-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\Clara =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\Conduit =>PUP.Optional.Conduit HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP =>PUP.Optional.GamesDesktop HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Wow6432Node\GoHD =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\GoHD-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\HighDefAction =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\I - Cinema-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\IHProtect =>PUP.Optional.AgentODR HKLM\SOFTWARE\Wow6432Node\Iminent =>PUP.Optional.IMBouster HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKLM\SOFTWARE\Wow6432Node\omniboxesSoftware =>PUP.Optional.Omniboxes HKLM\SOFTWARE\Wow6432Node\PhraseProfessor_1.10.0.24 =>PUP.Optional.Generic HKLM\SOFTWARE\Wow6432Node\SearchProtect =>PUP.Optional.SearchProtect HKLM\SOFTWARE\Wow6432Node\searchult =>PUP.Optional.Generic HKLM\SOFTWARE\Wow6432Node\shopperz100920151159 =>PUP.Optional.Shopperz HKLM\SOFTWARE\Wow6432Node\SupDp =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\supTab =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\supWindowsMangerProtect =>PUP.Optional.WpManager HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak HKLM\SOFTWARE\Wow6432Node\Tencent =>PUP.Optional.TencentAddressBar HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro HKLM\SOFTWARE\Wow6432Node\WordShark_1.10.0.20 =>PUP.Optional.WordShark HKLM\SOFTWARE\Wow6432Node\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer HKLM\SOFTWARE\Wow6432Node\YorkNewCin =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\ZoomWebLists =>PUP.Optional.Zoom HKCU\SOFTWARE\AnyProtect =>PUP.Optional.AnyProtect HKCU\SOFTWARE\ArenaHD =>PUP.Optional.CrossRider HKCU\SOFTWARE\AskPartnerNetwork =>Toolbar.AskBar HKCU\SOFTWARE\CinemaPlus-3.2cV10.09-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\CinemaPlus-3.2cV11.09-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\Crossbrowse =>PUP.Optional.CrossBrowse HKCU\SOFTWARE\CrossBrowser =>PUP.Optional.CrossBrowser HKCU\SOFTWARE\DailyPcClean =>PUP.Optional.DailyPCClean HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate HKCU\SOFTWARE\GoHD-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\HighDefAction =>PUP.Optional.CrossRider HKCU\SOFTWARE\HomeTab =>PUP.Optional.CertifiedToolbar HKCU\SOFTWARE\I - Cinema-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKCU\SOFTWARE\Linkey =>PUP.Optional.LinkeySearch HKCU\SOFTWARE\QyGameClient =>PUP.Optional.IQIYIVideo HKCU\SOFTWARE\SearchProtectWS =>PUP.Optional.SearchProtect HKCU\SOFTWARE\SimplyTech =>PUP.Optional.SimplyTech HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak HKCU\SOFTWARE\Tencent =>PUP.Optional.TencentAddressBar HKCU\SOFTWARE\TNT2 =>PUP.Optional.TidyNetwork HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive HKCU\SOFTWARE\WajIEnhance =>PUP.Optional.Wajam HKCU\SOFTWARE\YorkNewCin =>PUP.Optional.CrossRider HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider HKCU\SOFTWARE\AppDataLow\Software\SmartWeb =>PUP.Optional.SmartWebSearch C:\Program Files (x86)\96AC97A6-1441923651-2C10-C207-AC9E17DFFAC5 =>PUP.Optional.CrossRider C:\Program Files (x86)\AnyProtectEx =>PUP.Optional.AnyProtect C:\Program Files (x86)\ASP =>PUP.Optional.AdvancedSystemProtector C:\Program Files (x86)\CinemaPlus-3.2cV11.09 =>PUP.Optional.CrossRider C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate C:\Program Files (x86)\GoHD =>PUP.Optional.CrossRider C:\Program Files (x86)\I - Cinema =>PUP.Optional.CrossRider C:\Program Files (x86)\OLBPre =>PUP.Optional.MyPCBackup C:\Program Files (x86)\predm =>PUP.Optional.Downware C:\Program Files (x86)\SFK =>PUP.Optional.MyWebSearch C:\Program Files (x86)\Tencent =>PUP.Optional.TencentAddressBar C:\Program Files (x86)\Uniblue =>PUP.Optional.Uniblue C:\Program Files (x86)\WordSurfer_1.10.0.19 =>PUP.Optional.WordSurfer C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System~Protector =>PUP.Optional.AdvancedSystemProtector C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP =>PUP.Optional.GamesDesktop C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro =>PUP.Optional.RegistryPowerCleaner C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue =>PUP.Optional.Uniblue C:\ProgramData\4WdsManPro4 =>PUP.Optional.WdsManPro C:\ProgramData\7WdsManPro7 =>PUP.Optional.WdsManPro C:\ProgramData\eWdsManProe =>PUP.Optional.WdsManPro C:\ProgramData\IHProtectUpDate =>PUP.Optional.AgentODR C:\ProgramData\IQIYI Video =>PUP.Optional.IQIYIVideo C:\ProgramData\MWdsManProM =>PUP.Optional.WdsManPro C:\ProgramData\OWdsManProO =>PUP.Optional.WdsManPro C:\ProgramData\pWdsManProp =>PUP.Optional.WdsManPro C:\ProgramData\Systweak =>PUP.Optional.Systweak C:\ProgramData\Tencent =>PUP.Optional.TencentAddressBar C:\ProgramData\tWdsManProt =>PUP.Optional.WdsManPro C:\ProgramData\WindowsMangerProtect =>PUP.Optional.WpManager C:\Program Files (x86)\Common Files\Tencent =>PUP.Optional.TencentAddressBar C:\Users\rober\AppData\Roaming\AnyProtectEx =>PUP.Optional.AnyProtect C:\Users\rober\AppData\Roaming\IQIYI Video =>PUP.Optional.IQIYIVideo C:\Users\rober\AppData\Roaming\mystartsearch =>PUP.Optional.StartSearch C:\Users\rober\AppData\Roaming\RHEng =>PUP.Optional.Conduit C:\Users\rober\AppData\Roaming\systweak =>PUP.Optional.Systweak C:\Users\rober\AppData\Roaming\Tencent =>PUP.Optional.TencentAddressBar C:\Users\rober\AppData\Roaming\Uniblue =>PUP.Optional.Uniblue C:\Users\rober\AppData\Local\DesktopSearch =>PUP.Optional.DesktopSearch C:\Users\rober\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate C:\Users\rober\AppData\Local\SmartWeb =>PUP.Optional.SmartWebSearch C:\Users\rober\AppData\Local\SysassistByHotWheel =>PUP.Optional.Generic C:\Users\rober\AppData\Local\Systweak =>PUP.Optional.Systweak C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup =>PUP.Optional.AnyProtect C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Quick Access =>PUP.Optional.InternetQuickAccess C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter =>.Superfluous.SpyHunter C:\WINDOWS\Prefetch\ADVANCEDSYSTEMPROTECTOR.EXE-E30B6CE6.pf =>PUP.Optional.AdvancedSystemProtector C:\WINDOWS\Prefetch\ANYPROTECT.EXE-1996592C.pf =>PUP.Optional.AnyProtect C:\WINDOWS\Prefetch\BOBROWSER.EXE-7BB7AB57.pf =>PUP.Optional.BoBrowser C:\WINDOWS\Prefetch\CLARAUPDATER.EXE-875FA871.pf =>PUP.Optional.SupTab C:\WINDOWS\Prefetch\DESKTOPSEARCH_SOFT_PARTNER.EX-539B1EEB.pf =>PUP.Optional.DesktopSearch C:\WINDOWS\Prefetch\FLASHBEAT.EXE-7F5ED19D.pf =>PUP.Optional.FlashBeat C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-35F6B904.pf =>PUP.Optional.GlobalUpdate C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-8AF1FB91.pf =>PUP.Optional.GlobalUpdate C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-9034CA88.pf =>PUP.Optional.GlobalUpdate C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-A5FFDA83.pf =>PUP.Optional.GlobalUpdate C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-DC37E952.pf =>PUP.Optional.GlobalUpdate C:\WINDOWS\Prefetch\GLOBALUPDATECRASHHANDLER.EXE-68CB7B8C.pf =>PUP.Optional.GlobalUpdate C:\WINDOWS\Prefetch\OLBPRE.EXE-C6385661.pf =>PUP.Optional.MyPCBackup C:\WINDOWS\Prefetch\PREDM.EXE-1FCA533C.pf =>PUP.Optional.Downware C:\WINDOWS\Prefetch\PREDM.EXE-4366456F.pf =>PUP.Optional.Downware C:\WINDOWS\Prefetch\PREDM.TMP-19039B47.pf =>PUP.Optional.Downware C:\WINDOWS\Prefetch\PREDM.TMP-626FDBE5.pf =>PUP.Optional.Downware C:\WINDOWS\Prefetch\PREDM.TMP-DC27314D.pf =>PUP.Optional.Downware C:\WINDOWS\Prefetch\SMARTWEBAPP.EXE-C15B5E8C.pf =>PUP.Optional.SmartWebSearch C:\WINDOWS\Prefetch\SMARTWEBHELPER.EXE-D9CBB7C7.pf =>PUP.Optional.SmartWebSearch C:\WINDOWS\Prefetch\SPEEDUPMYPC-STANDALONE-SETUP.-2617F7D5.pf =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\Prefetch\SPEEDUPMYPC-STANDALONE-SETUP.-477C310D.pf =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\Prefetch\SPEEDUPMYPC.EXE-E9FC9CD7.pf =>PUP.Optional.SpeedUpMyPC C:\WINDOWS\Prefetch\SPYHUNTER-INSTALLER.EXE-3C8E00EF.pf =>.Superfluous.SpyHunter C:\WINDOWS\Prefetch\SPYHUNTER.4.3.32-PATCH.EXE-D2A57466.pf =>.Superfluous.SpyHunter C:\WINDOWS\Prefetch\SPYHUNTER.4.3.32-PATCH.EXE-D75FD585.pf =>.Superfluous.SpyHunter C:\WINDOWS\Prefetch\SPYHUNTER4.EXE-6272DFA2.pf =>.Superfluous.SpyHunter C:\WINDOWS\Prefetch\SPYHUNTER4.EXE-7BD5E907.pf =>.Superfluous.SpyHunter C:\WINDOWS\Prefetch\SYSTWEAKASP.EXE-DA3A3BD5.pf =>PUP.Optional.Systweak C:\WINDOWS\Prefetch\SYSTWEAKASP.TMP-C781DD29.pf =>PUP.Optional.Systweak C:\WINDOWS\Prefetch\SYSTWEAKASP.TMP-EC0918C3.pf =>PUP.Optional.Systweak C:\WINDOWS\Prefetch\TENCENTDL.EXE-D4BCC9C9.pf =>PUP.Optional.TencentAddressBar C:\WINDOWS\Prefetch\WAJAM.EXE-35E970A1.pf =>PUP.Optional.Wajam C:\WINDOWS\Prefetch\WAJAM_64.EXE-39BDE776.pf =>PUP.Optional.Wajam C:\WINDOWS\Prefetch\WAJAM_DOWNLOAD_V2.EXE-275BA10E.pf =>PUP.Optional.Wajam C:\WINDOWS\Prefetch\WAJAM_DOWNLOAD_V2.EXE-BDAA0249.pf =>PUP.Optional.Wajam C:\WINDOWS\Prefetch\WDSMANPRO.EXE-093D3707.pf =>PUP.Optional.WdsManPro C:\WINDOWS\Prefetch\WDSMANPRO.EXE-0F82C291.pf =>PUP.Optional.WdsManPro C:\WINDOWS\Prefetch\WDSMANPRO.EXE-55F73D9F.pf =>PUP.Optional.WdsManPro C:\WINDOWS\Prefetch\WDSMANPRO.EXE-6F0D6BC7.pf =>PUP.Optional.WdsManPro C:\WINDOWS\Prefetch\WDSMANPRO.EXE-B581E6D5.pf =>PUP.Optional.WdsManPro C:\WINDOWS\Prefetch\WDSMANPRO.EXE-E925BF45.pf =>PUP.Optional.WdsManPro C:\WINDOWS\Prefetch\WORDSURFERAUTOUPDATECLIENT.EX-4E78B08A.pf =>PUP.Optional.WordSurfer C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-587E245A.pf =>PUP.Optional.WpManager C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-5AC96A75.pf =>PUP.Optional.WpManager C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-BC734F0B.pf =>PUP.Optional.WpManager C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-C1A4000D.pf =>PUP.Optional.WpManager C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-D18D8379.pf =>PUP.Optional.WpManager C:\WINDOWS\Prefetch\WPM_V20.0.0.2301.EXE-E6D5D969.pf =>PUP.Optional.WpManager C:\WINDOWS\System32\drivers\bsdriver.sys =>PUP.Optional.Shopperz C:\WINDOWS\System32\drivers\ppfd_vw_1_10_0_24.sys =>PUP.Optional.Generic C:\WINDOWS\System32\drivers\wsafd_1_10_0_19.sys =>PUP.Optional.WordSurfer C:\WINDOWS\System32\drivers\wsfd_vw_1_10_0_20.sys =>PUP.Optional.Generic C:\Users\rober\Downloads\SpyHunter-Installer.exe =>.Superfluous.SpyHunter C:\Users\rober\AppData\Roaming\systweak\regclean pro\Version 6.1\backup3.bin =>PUP.Optional.RegistryPowerCleaner C:\Users\rober\AppData\Roaming\systweak\regclean pro\Version 6.1\backup4.bin =>PUP.Optional.RegistryPowerCleaner C:\Users\rober\AppData\Roaming\systweak\regclean pro\Version 6.1\backup6.bin =>PUP.Optional.RegistryPowerCleaner C:\Users\rober\AppData\Roaming\mystartsearch\UninstallManager.exe =>PUP.Optional.StartSearch C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe =>PUP.Optional.IQIYIVideo C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\QyUpdate\IQIYIsetup_update_201506041.exe =>PUP.Optional.IQIYIVideo C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\GpUpdate\GeePlayerSetup_update20150907.exe =>PUP.Optional.IQIYIVideo C:\Users\rober\AppData\Local\Systweak\Advanced System Protector\aspcontexthelper64.dll =>PUP.Optional.AdvancedSystemProtector C:\Users\rober\AppData\Local\SmartWeb\__u.exe =>PUP.Optional.SmartWebSearch C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\setup[1].exe =>PUP.Optional.CrossRider C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\VZNQ74JJ\SmartWebInstaller[1].exe =>PUP.Optional.SmartWebSearch C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\ORDLA5PN\AnyProtectSetup[1].exe =>PUP.Optional.AnyProtect C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\ORDLA5PN\SpeedUpMyPC-standalone-setup[1].exe =>PUP.Optional.SpeedUpMyPC C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\AnyProtect[1].exe =>PUP.Optional.AnyProtect C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\N1Y1CXXC\VuuPC_VO2_8907[1].exe =>PUP.Optional.VuuPC C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\cmi_mystartsearch[1].exe =>PUP.Optional.StartSearch C:\Users\rober\AppData\Local\Microsoft\Windows\INetCache\IE\F35YMC4Z\wordsurfer-setup-1.10.0.19[1].exe =>PUP.Optional.WordSurfer C:\Users\rober\AppData\Roaming\IQIYI Video\LStyle\GpUpdate.exe =>PUP.Optional.IQIYIVideo C:\IQIYI Video\GeePlayer\GeePlayer.exe =>PUP.Optional.IQIYIVideo C:\IQIYI Video\LStyle\QyClient.exe =>PUP.Optional.IQIYIVideo C:\IQIYI Video\LStyle\QyWebPlayer.exe =>PUP.Optional.IQIYIVideo C:\IQIYI Video\LStyle\QyPlayer.exe =>PUP.Optional.IQIYIVideo C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe =>PUP.Optional.TencentAddressBar C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe =>PUP.Optional.TencentAddressBar HKLM\Software\Classes\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E =>PUP.Optional.GlobalUpdate HKLM\Software\Classes\Installer\Features\93BAD29AC2E44034A96BCB446EB8552E =>PUP.Optional.GlobalUpdate HKLM\SYSTEM\CurrentControlSet\Services\globalUpdatem =>PUP.Optional.GlobalUpdate HKLM\SYSTEM\CurrentControlSet\Services\WdsManPro =>PUP.Optional.WpManager C:\ProgramData\OWdsManProO\WdsManPro.exe =>PUP.Optional.WpManager HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASAPI32 =>PUP.Optional.WordSurfer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSurferAutoUpdateClient_RASMANCS =>PUP.Optional.WordSurfer ---\\ Resumo dos elementos encontrados na sua estação de trabalho (50) - 0s http://www.nicolascoolman.fr/blog =>Hijacker.Hosts http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/blog =>PUP.Optional.WdsManPro http://www.nicolascoolman.fr/pup-smartwebsearch/ =>PUP.Optional.SmartWebSearch http://www.nicolascoolman.fr/pup-mypcbackup/ =>PUP.Optional.MyPCBackup http://www.nicolascoolman.fr/pup-wajam/ =>PUP.Optional.Wajam http://www.nicolascoolman.fr/blog =>PUP.Optional.SpeedUpMyPC http://www.nicolascoolman.fr/blog =>PUP.Optional.IQIYIVideo http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate http://www.nicolascoolman.fr/hijacker-browsers/ =>PUP.Optional.Browser http://www.nicolascoolman.fr/blog =>PUP.Optional.Omniboxes http://www.nicolascoolman.fr/pup-anyprotect/ =>PUP.Optional.AnyProtect http://www.nicolascoolman.fr/blog =>.Superfluous.SpyHunter http://www.nicolascoolman.fr/pup-advancedsystemprotector/ =>PUP.Optional.AdvancedSystemProtector http://www.nicolascoolman.fr/blog =>PUP.Optional.FlashBeat http://www.nicolascoolman.fr/adware-mywebsearch/ =>PUP.Optional.MyWebSearch http://www.nicolascoolman.fr/pup-systweak/ =>PUP.Optional.Systweak http://www.nicolascoolman.fr/blog =>PUP.Optional.BoBrowser http://www.nicolascoolman.fr/blog =>PUP.Optional.InternetQuickAccess http://www.nicolascoolman.fr/rogue-registrypowercleaner/ =>PUP.Optional.RegistryPowerCleaner http://www.nicolascoolman.fr/blog =>PUP.Optional.Shopperz http://www.nicolascoolman.fr/blog =>Heuristic.Graftor http://www.nicolascoolman.fr/blog =>Heuristic.PullUpdate http://www.nicolascoolman.fr/blog =>PUP.Optional.WordSurfer http://www.nicolascoolman.fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch http://www.nicolascoolman.fr/blog =>PUP.Optional.Uniblue http://www.nicolascoolman.fr/blog =>Toolbar.AskBar http://www.nicolascoolman.fr/pup-suptab/ =>PUP.Optional.SupTab http://www.nicolascoolman.fr/toolbar-conduit/ =>PUP.Optional.Conduit http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowse http://www.nicolascoolman.fr/blog =>PUP.Optional.GamesDesktop http://www.nicolascoolman.fr/blog =>PUP.Optional.AgentODR http://www.nicolascoolman.fr/adware-imbooster/ =>PUP.Optional.IMBouster http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowserExtensions http://www.nicolascoolman.fr/blog =>PUP.Optional.Generic http://www.nicolascoolman.fr/pup-searchprotect/ =>PUP.Optional.SearchProtect http://www.nicolascoolman.fr/pup-wpmanager/ =>PUP.Optional.WpManager http://www.nicolascoolman.fr/adware-tencentaddressbar/ =>PUP.Optional.TencentAddressBar http://www.nicolascoolman.fr/spyware-agenceexclusive/ =>PUP.Optional.AgenceExclusive http://www.nicolascoolman.fr/pup-wordshark/ =>PUP.Optional.WordShark http://www.nicolascoolman.fr/blog =>PUP.Optional.Zoom http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowser http://www.nicolascoolman.fr/pup-optional-dailypcclean/ =>PUP.Optional.DailyPCClean http://www.nicolascoolman.fr/pup-certifiedtoolbar/ =>PUP.Optional.CertifiedToolbar http://www.nicolascoolman.fr/pup-linkeysearch/ =>PUP.Optional.LinkeySearch http://www.nicolascoolman.fr/blog =>PUP.Optional.SimplyTech http://www.nicolascoolman.fr/adware-tidynetwork/ =>PUP.Optional.TidyNetwork http://www.nicolascoolman.fr/adware-downware/ =>PUP.Optional.Downware http://www.nicolascoolman.fr/blog =>PUP.Optional.DesktopSearch http://www.nicolascoolman.fr/pup-vuupc/ =>PUP.Optional.VuuPC ~ End of the scan, 23634 items in 62 seconds (1524)(0)()