cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.10.22.154 Por Nicolas Coolman (2015/10/22)
~ iniciado por Mario (Administrator) (2015/10/25 15:15:16)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Status da versão: Version OK
~ Modo: Scanner
~ Relatório: C:\Users\Mario\Desktop\ZHPDiag.txt
~ Relatório: C:\Users\Mario\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Inicialização do sistema: Normal (Normal boot)
Windows 8.1 Pro, 64-bit (Build 9600)

---\\ Navegadores Internet (3) - 0s
GCIE: Google Chrome v41.0.2272.76
MFIE: Mozilla Firefox 41.0.2 (x86 pt-BR) v41.0.2
MSIE: Internet Explorer v11.0.9600.18053

---\\ Informações sobre os produtos Windows (3) - 4s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ Softwares de proteçao do sistema (2) - 6s
Avast Free Antivirus v10.4.2233
Windows Defender (Deactivate)

---\\ HKCU & HKLM Software Keys (1) - 7s
McAfee Security Scan Plus v3.11.163.2

---\\ Softwares d'optimização do sistema (1) - 7s
CCleaner v4.19

---\\ Monitoramento dos softwares (1) - 7s
Adobe Flash Player 19 NPAPI

---\\ Informações sobre o sistema (6) - 0s
~ Operating System: AMD64 Family 21 Model 2 Stepping 0, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4171.304 MB (43% free)
~ System Restore: Activé (Enable)
~ System drive C: has 371 GB free of 476 GB

---\\ Modo de conexão ao sistema (3) - 0s
~ Computer Name: VGAMER
~ User Name: Mario
~ Logged in as Administrator

---\\ Enumeração das unidades dos discos (1) - 0s
~ Drive C: has 371 GB free of 476 GB (System)

---\\ Estado do Centro de Segurança do Windows (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Pesquisa particular de ficheiros genéricos (24) - 3s
[MD5.C10A66189DC8C090E7C84873EDCEBC88] - (.Microsoft Corporation - Windows Explorer.) () -- C:\Windows\Explorer.exe [2501368] ©
[MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [54784] ©
[MD5.A570A64292214C43E0BA50E6A72A6380] - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) () -- C:\Windows\System32\Wininit.exe [145920] ©
[MD5.F6A075F2D69D9AFD14C6B79DF5C717D6] - (.Microsoft Corporation - Internet Extensions para Win32.) () -- C:\Windows\System32\wininet.dll [2487808] ©
[MD5.EC498BAE1F0D3E0E401C963F8D76C437] - (.Microsoft Corporation - Aplicativo de Logon do Windows.) () -- C:\Windows\System32\Winlogon.exe [572416] ©
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) () -- C:\Windows\System32\sppcomapi.dll [447488] ©
[MD5.A5675939CF0F99B20B5A3CFCC3C1B46A] - (.Microsoft Corporation - DLL da API de cliente DNS.) () -- C:\Windows\System32\dnsapi.dll [657920] ©
[MD5.BD9C7A068C46053F8747CEA73B5930AB] - (.Microsoft Corporation - DLL da API de cliente DNS.) () -- C:\Windows\Syswow64\dnsapi.dll [498688] ©
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [563200] ©
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [26464] ©
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [88576] ©
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [164352] ©
[MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [134144] ©
[MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [76800] ©
[MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - (.Microsoft Corporation - Driver de porta i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [108544] ©
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [142848] ©
[MD5.6FBDF2B1B025A8E6E069234362FFFFB7] - (.Microsoft Corporation - Minirdr SMB do Windows NT.) () -- C:\Windows\System32\drivers\MRxSmb.sys [401408] ©
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [282624] ©
[MD5.7F68063A5A0461E02BC860CE0E6BFDDC] - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) () -- C:\Windows\System32\drivers\ntfs.sys [2025792] ©
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Driver de porta paralela.) () -- C:\Windows\System32\drivers\Parport.sys [94208] ©
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [120832] ©
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Micros.) () -- C:\Windows\System32\drivers\rdpdr.sys [195584] ©
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [107520] ©
[MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) () -- C:\Windows\System32\drivers\volsnap.sys [310080] ©

---\\ Processos lançados (30) - 2s
[MD5.F029A2C032B4A50DEBB21312CFF76189] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 355.8.) -- C:\Windows\system32\nvvsvc.exe [937776] [PID.908] ©
[MD5.9FAA9DED1594A643DC7A53C3B15CC678] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1251120] [PID.976] ©
[MD5.F029A2C032B4A50DEBB21312CFF76189] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 355.8.) -- C:\Windows\system32\nvvsvc.exe [937776] [PID.984] ©
[MD5.11120878E5276B367E1A10FF8C9B595B] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600] [PID.1236] ©
[MD5.EBBCD5DFBB1DE70E8F4AF8FA59E401FD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462184] [PID.1568] ©
[MD5.5EBFF8D302047F4709F3A4F1231236E9] - (.BlueStack Systems, Inc. - BlueStacks Updater Service.) -- C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [831096] [PID.1660] ©
[MD5.D3C40989B164358F5BAA11EB7F605390] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155376] [PID.1868] ©
[MD5.D6BF6FD055BD719F3D62E51B90857159] - (.LogMeIn, Inc. - LMIGuardianSvc.) -- C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552] [PID.1960] ©
[MD5.930AE35B57C33F361AF045D220229063] - (.NVIDIA Corporation - NVIDIA Network Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688] [PID.2012] ©
[MD5.B2C3D31934FAFA20EE8ED1977651E871] - (.NVIDIA Corporation - NVIDIA Streamer Service.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568816] [PID.1216] ©
[MD5.014CC63C16A15AADC016E22D444E4D6C] - (.Baidu Inc. - spark.) -- C:\Program Files (x86)\baidu\Spark\sparkservice.exe [84160] [PID.1804]
[MD5.2ADED86ED9B92885378467CFEE9ABE8F] - (.LogMeIn Inc. - Hamachi Client Tunneling Engine.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2545512] [PID.2052] ©
[MD5.CF5F47B708C539A40EBBDD7E4675FADA] - (.Avast Software - AvastVirtualBox Interface.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4048280] [PID.3028] ©
[MD5.11AFDF4FC4B0906CEBD98D672F438939] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [7575344] [PID.3312] ©
[MD5.3B21300676CD2FCF13D0E6BDE1CC6A09] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe [21983024] [PID.3004] ©
[MD5.FEDF59A44767480267C5615C46F0FBA5] - (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2654512] [PID.516] ©
[MD5.6DC5DB99502C9BAC84EFAA02BF841EA4] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2448176] [PID.1600] ©
[MD5.0671EAE125EA82EF51F5BE4916B2B3A3] - (.NVIDIA Corporation - NVIDIA Capture Server.) -- C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe [4169520] [PID.2964] ©
[MD5.9D0D72B696B8CDF9AE368E542FD042CE] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Mario\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2030912] [PID.1596] ©
[MD5.02B8BC2531917B205D509E6D8661DAFF] - (.LogMeIn Inc. - Hamachi Client Application.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5579624] [PID.4224] ©
[MD5.D5218EE66173405B26B716EBA68133F6] - (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe [2901584] [PID.4420] ©
[MD5.2C27A179F45F8A0CCED7EAD075AA640C] - (.Valve Corporation - Steam Client WebHelper.) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe [1835088] [PID.4340] ©
[MD5.2C27A179F45F8A0CCED7EAD075AA640C] - (.Valve Corporation - Steam Client WebHelper.) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe [1835088] [PID.5316] ©
[MD5.2C27A179F45F8A0CCED7EAD075AA640C] - (.Valve Corporation - Steam Client WebHelper.) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe [1835088] [PID.5956] ©
[MD5.14DCA74CB34502CA919966F31FBB8B0D] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [377000] [PID.4036] ©
[MD5.DC8DC7ED86A259614D3B2186B2F841EB] - (.Spotify Ltd - Spotify.) -- C:\Users\Mario\AppData\Roaming\Spotify\Spotify.exe [7736128] [PID.3488] ©
[MD5.6E28D341B7691A45145C0AA27587D635] - (.Spotify Ltd - SpotifyCrashService.) -- C:\Users\Mario\AppData\Roaming\Spotify\SpotifyCrashService.exe [840512] [PID.4412] ©
[MD5.DC8DC7ED86A259614D3B2186B2F841EB] - (.Spotify Ltd - Spotify.) -- C:\Users\Mario\AppData\Roaming\Spotify\Spotify.exe [7736128] [PID.5812] ©
[MD5.DC8DC7ED86A259614D3B2186B2F841EB] - (.Spotify Ltd - Spotify.) -- C:\Users\Mario\AppData\Roaming\Spotify\Spotify.exe [7736128] [PID.5544] ©
[MD5.231AE3BE35DFA790FE484CCA354BCD15] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Mario\Desktop\ZHPDiag3.exe [1958912] [PID.3952] ©

---\\ Google Chrome, Arranque,Pesquisa,Extensões (11) - 1s
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aleggpabliehgbeagmfhnodcijcmbonb] Dr.Web
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gomekmidlodglbbmalcneegieacbdmki] Avast Online Security
G2 - GCE: Preference [User Data\Default] [llihccomjnidgdibbpciaajkednnglpm] SmartSaver+ 15 =>PUP.Optional.CrossRider
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (6) - 1s
M0 - MFSP: prefs.js [Mario - 5zlx3pi4.default-1415703582551] http://google.com.br/
P2 - EXT FILE: (...) -- C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\5zlx3pi4.default-1415703582551\extensions\firefox@mega.co.nz.xpi
P2 - EXT FILE: (...) -- C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\5zlx3pi4.default-1415703582551\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll ©
P2 - FPN: [HKLM] [@esn/npbattlelog,version=2.5.1] - (.EA Digital Illusions CE AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll ©

---\\ Internet Explorer, Arranque, Pesquisa, Phishing (19) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer, Gestão do Proxy (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Análise das linhas, Carregamento Automático de programas (3) - 1s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ©

---\\ Redireção do ficheiro Hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (1)

---\\ Browser Helper Objects do navegador (6) - 0s
O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Orphean)
O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ©
O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll ©
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL ©
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} (Orphean)

---\\ Aplicações iniciadas por registo & pastas (9) - 0s
O4 - HKLM\..\Run: [ShadowPlay] . (.Microsoft Corporation - Processo de host do Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe ©
O4 - HKLM\..\Run: [XboxStat] . (.Microsoft Corporation - XBoxStat.exe.) -- C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe ©
O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe ©
O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Mario\AppData\Roaming\Spotify\SpotifyWebHelper.exe ©
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe ©
O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] . (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe ©
O4 - HKLM\..\Wow6432Node\Run: [LogMeIn Hamachi Ui] . (.LogMeIn Inc. - Hamachi Client Application.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe ©
O4 - HKLM\..\Wow6432Node\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe ©
O4 - HKUS\S-1-5-21-2302439242-1255324135-1533517511-1001\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Mario\AppData\Roaming\Spotify\SpotifyWebHelper.exe ©

---\\ Alteração Dominio/Clientes DNS (6) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.25.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.25.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4, =>.Google Public DNS
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4,192.168.25.1 =>.Google Public DNS

---\\ Protocolo adicional (23) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: skypec2c [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll ©
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll ©
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll ©
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll ©
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL ©

---\\ Serviços NT não Microsoft e não desativados (12) - 1s
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe ©
O23 - Service: Serviço do Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe ©
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc. - BlueStacks Log Rotator Service.) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe ©
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) . (.BlueStack Systems, Inc. - BlueStacks Updater Service.) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe ©
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe ©
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) . (.LogMeIn Inc. - Hamachi Client Tunneling Engine.) - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe ©
O23 - Service: LMIGuardianSvc (LMIGuardianSvc) . (.LogMeIn, Inc. - LMIGuardianSvc.) - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe ©
O23 - Service: NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation - NVIDIA Network Service.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe ©
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation - NVIDIA Streamer Service.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe ©
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 355.8.) - C:\Windows\system32\nvvsvc.exe ©
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe ©
O23 - Service: Baidu Spark Service (SparkSvc) . (.Baidu Inc. - spark.) - C:\Program Files (x86)\baidu\Spark\sparkservice.exe

---\\ Tarefas planificadas automaticamente (19) - 5s
[MD5.1D440E5823170907AADEFB04239A492F] [APT] [94A46359-5537-4201-BEFD-1EC63DFD0941] (.ShenZhen Enode Techology co,.Ltd.) -- C:\ProgramData\WeatherMini.exe [1029096] ©
[MD5.8C194A201698B4B4F77D974549819D1F] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000] ©
[MD5.D9E35285D8CCE58241038E5B23507DAB] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [1382112] ©
[MD5.947835240308F523C9D980C89D35E76D] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4825880] ©
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] ©
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] ©
[MD5.7E215C9AB8E6FFB3A8BA38045BCBEE44] [APT] [SparkUpdater] (.Baidu.com, Inc..) -- C:\Program Files (x86)\baidu\Spark\SparkUpdate.exe [1359040]
[MD5.14DCA74CB34502CA919966F31FBB8B0D] [APT] [{859989E3-1C62-4294-A651-7DF84D128BDD}] (.Mozilla Corporation.) -- c:\program files (x86)\mozilla firefox\firefox.exe [377000] ©
[MD5.FCAA3FC6964A3012A2F725284CF6DDD5] [APT] [AVAST Software\Avast settings backup] (.AVAST Software.) -- C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [180096] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [902] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1086] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1090] ©
O39 - APT: 94A46359-5537-4201-BEFD-1EC63DFD0941 - (.ShenZhen Enode Techology co,.Ltd.) -- C:\Windows\System32\Tasks\94A46359-5537-4201-BEFD-1EC63DFD0941 [3846] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3792] ©
O39 - APT: avast! Emergency Update - (.AVAST Software.) -- C:\Windows\System32\Tasks\avast! Emergency Update [3926] ©
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2772] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3828] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4064] ©
O39 - APT: SparkUpdater - (.Baidu.com, Inc..) -- C:\Windows\System32\Tasks\SparkUpdater [4050]

---\\ Software instalados (97) - 13s
O42 - Logiciel: Nexus Mod Manager - (.Black Tree Gaming.) [HKLM][64Bits] -- 6af12c54-643b-4752-87d0-8335503010de_is1 ©
O42 - Logiciel: 7-Zip 15.09 beta (x64) - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip ©
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner ©
O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan ©
O42 - Logiciel: Microsoft Xbox 360 Accessories 1.2 - (.Microsoft.) [HKLM][64Bits] -- {070C55FA-FB9D-46DD-B30B-4B520A83A66A} ©
O42 - Logiciel: Java 7 Update 76 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F06417076FF} ©
O42 - Logiciel: Java 8 Update 45 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418045F0} ©
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} ©
O42 - Logiciel: Oracle VM VirtualBox 4.3.18 - (.Oracle Corporation.) [HKLM][64Bits] -- {74B7E6F9-DCAC-4ADB-B2D0-EEFDD1B5AC25} ©
O42 - Logiciel: NVIDIA Driver do 3D Vision 355.82 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision ©
O42 - Logiciel: NVIDIA Driver de gráficos 355.82 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver ©
O42 - Logiciel: NVIDIA GeForce Experience 2.5.15.46 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience ©
O42 - Logiciel: NVIDIA Driver de controle do 3D Vision 352.65 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB ©
O42 - Logiciel: NVIDIA Software do sistema PhysX 9.15.0428 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX ©
O42 - Logiciel: NVIDIA Driver de áudio HD 1.3.34.3 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver ©
O42 - Logiciel: NVIDIA Áudio Virtual Miracast 355.82 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio ©
O42 - Logiciel: Vegas Pro 13.0 (64-bit) - (.Sony.) [HKLM][64Bits] -- {D264BD11-6A9B-11E4-A4F7-F04DA23A5C58} ©
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM][64Bits] -- {D66B7840-6A9B-11E4-8FED-F04DA23A5C58} ©
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR ©
O42 - Logiciel: Adobe Flash Player 19 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI ©
O42 - Logiciel: Adobe Photoshop CS6 - (.© The Computer Guy Tony.) [HKLM][64Bits] -- Adobe Photoshop CS6
O42 - Logiciel: Audacity 2.0.5 - (.Audacity Team.) [HKLM][64Bits] -- Audacity_is1 ©
O42 - Logiciel: Avast Free Antivirus - (.AVAST Software.) [HKLM][64Bits] -- Avast ©
O42 - Logiciel: Bandicam - (.Bandisoft.com.) [HKLM][64Bits] -- Bandicam ©
O42 - Logiciel: Bandisoft MPEG-1 Decoder - (.Bandisoft.com.) [HKLM][64Bits] -- BandiMPEG1 ©
O42 - Logiciel: BlueStacks App Player - (.BlueStack Systems, Inc..) [HKLM][64Bits] -- BlueStacks App Player ©
O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 ©
O42 - Logiciel: Cube World - (.Friends in War.) [HKLM][64Bits] -- Cube World1 ©
O42 - Logiciel: DAEMON Tools Lite - (.Disc Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite ©
O42 - Logiciel: Dark Souls 2 - (.R.G. Mechanics, markfiter.) [HKLM][64Bits] -- Dark Souls 2_R.G. Mechanics_is1 ©
O42 - Logiciel: Dxtory version 2.0.122 - (.Dxtory Software.) [HKLM][64Bits] -- Dxtory2.0_is1 ©
O42 - Logiciel: FL Studio 11 - (.Image-Line.) [HKLM][64Bits] -- FL Studio 11 ©
O42 - Logiciel: FlowStone FL 3.0 - (...) [HKLM][64Bits] -- FlowStone
O42 - Logiciel: Dark Souls Prepare to Die Edition - (.NAMCO BANDAI Games Europe S.A.S..) [HKLM][64Bits] -- GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200} ©
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome ©
O42 - Logiciel: IL Shared Libraries - (.Image-Line.) [HKLM][64Bits] -- IL Shared Libraries ©
O42 - Logiciel: LogMeIn Hamachi - (.LogMeIn, Inc..) [HKLM][64Bits] -- LogMeIn Hamachi ©
O42 - Logiciel: Mozilla Firefox 41.0.2 (x86 pt-BR) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 41.0.2 (x86 pt-BR) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService ©
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo ©
O42 - Logiciel: PaintTool SAI - (.Eddie Sekiguchi Softwares.) [HKLM][64Bits] -- PaintTool SAI1.1.0
O42 - Logiciel: Baidu Browser - (.Baidu Inc..) [HKLM][64Bits] -- Spark
O42 - Logiciel: Stay Live 2000 - (.Gregory Braun -- Software Design.) [HKLM][64Bits] -- Stay Live 2000
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam ©
O42 - Logiciel: BEEP - (.Big Fat Alien.) [HKLM][64Bits] -- Steam App 104200
O42 - Logiciel: Terraria - (.Re-Logic.) [HKLM][64Bits] -- Steam App 105600 ©
O42 - Logiciel: Neverwinter - (.Cryptic Studios.) [HKLM][64Bits] -- Steam App 109600 ©
O42 - Logiciel: Magicka: Wizard Wars - (.Paradox North.) [HKLM][64Bits] -- Steam App 202090
O42 - Logiciel: Warframe - (.Digital Extremes.) [HKLM][64Bits] -- Steam App 230410 ©
O42 - Logiciel: Path of Exile - (.Grinding Gear Games.) [HKLM][64Bits] -- Steam App 238960 ©
O42 - Logiciel: Epigenesis - (.Dead Shark Triplepunch.) [HKLM][64Bits] -- Steam App 244590
O42 - Logiciel: Blockstorm - (.GhostShark.) [HKLM][64Bits] -- Steam App 263060
O42 - Logiciel: Fistful of Frags - (.Fistful of Frags Team.) [HKLM][64Bits] -- Steam App 265630
O42 - Logiciel: Red Crucible: Firestorm - (...) [HKLM][64Bits] -- Steam App 298240
O42 - Logiciel: Trove - (.Trion Worlds.) [HKLM][64Bits] -- Steam App 304050 ©
O42 - Logiciel: Unturned - (.Nelson Sexton.) [HKLM][64Bits] -- Steam App 304930 ©
O42 - Logiciel: Double Action: Boogaloo - (.Double Action Factory.) [HKLM][64Bits] -- Steam App 317360
O42 - Logiciel: 4th Annual Saxxy Awards - (...) [HKLM][64Bits] -- Steam App 321770
O42 - Logiciel: DARK SOULS™ II: Scholar of the First Sin - (.FromSoftware, Inc.) [HKLM][64Bits] -- Steam App 335300 ©
O42 - Logiciel: Grimoire: Manastorm - (.Omniconnection.) [HKLM][64Bits] -- Steam App 335430
O42 - Logiciel: Fork Parker's Holiday Profit Hike - (.Dodge Roll.) [HKLM][64Bits] -- Steam App 339120
O42 - Logiciel: Among Ripples - (.Eat Create Sleep.) [HKLM][64Bits] -- Steam App 341720
O42 - Logiciel: AdVenture Capitalist - (.Hyper Hippo Games.) [HKLM][64Bits] -- Steam App 346900 ©
O42 - Logiciel: Clicker Heroes - (...) [HKLM][64Bits] -- Steam App 363970
O42 - Logiciel: Sakura Clicker - (.Winged Cloud.) [HKLM][64Bits] -- Steam App 383080
O42 - Logiciel: One Way To Die: Steam Edition - (.CoaguCo Industries.) [HKLM][64Bits] -- Steam App 388490
O42 - Logiciel: Garry's Mod - (.Facepunch Studios.) [HKLM][64Bits] -- Steam App 4000 ©
O42 - Logiciel: Counter-Strike: Global Offensive - (.Valve.) [HKLM][64Bits] -- Steam App 730 ©
O42 - Logiciel: WinRAR 5.11 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver ©
O42 - Logiciel: ZD Soft Screen Recorder - (.ZD Soft.) [HKLM][64Bits] -- {101CC777-634C-42AF-AF95-7A0282ABF247}
O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} ©
O42 - Logiciel: Java 8 Update 45 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218045F0} ©
O42 - Logiciel: Microsoft XNA Framework Redistributable 4.0 - (.Microsoft Corporation.) [HKLM][64Bits] -- {2BFC7AA0-544C-4E3A-8796-67F3BE655BE9} ©
O42 - Logiciel: BlueStacks Notification Center - (.BlueStack Systems, Inc..) [HKLM][64Bits] -- {3792811C-832F-4392-B44A-24092901EDDC} ©
O42 - Logiciel: Adobe After Effects CS6 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {4817D846-700B-474E-A31B-80892B3E92E3} ©
O42 - Logiciel: System Requirements Lab Detection - (.Husdawg, LLC.) [HKLM][64Bits] -- {4DE2EA64-65F2-47C0-B72E-3257EEF4625E} ©
O42 - Logiciel: Dark Souls Prepare to Die Edition - (.NAMCO BANDAI Games Europe S.A.S..) [HKLM][64Bits] -- {4E4D0FA1-F880-4CCB-999A-501000008200} ©
O42 - Logiciel: LogMeIn Hamachi - (.LogMeIn, Inc..) [HKLM][64Bits] -- {517E7DBD-7A5B-4B7F-B137-82AB4DAD68FC} ©
O42 - Logiciel: Grand Theft Auto IV - (.Rockstar Games Inc..) [HKLM][64Bits] -- {5454083B-1308-4485-BF17-1110000D8301} ©
O42 - Logiciel: Grand Theft Auto IV - (.Rockstar Games Inc..) [HKLM][64Bits] -- {5454083B-1308-4485-BF17-1110000D8302} ©
O42 - Logiciel: Grand Theft Auto IV - (.Rockstar Games Inc..) [HKLM][64Bits] -- {5454083B-1308-4485-BF17-1110000D8303} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: Microsoft Games for Windows Marketplace - (.Microsoft Corporation.) [HKLM][64Bits] -- {67F42018-F647-4D3C-BE62-F8CB4FE2FCD5} ©
O42 - Logiciel: Skype™ 7.8 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {6A0549A9-1B96-498C-ACBC-3943001FEB19} ©
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} ©
O42 - Logiciel: Microsoft Games for Windows - LIVE Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ©
O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AF37176A-78CA-545B-34EF-8B6A21514DD1} ©
O42 - Logiciel: Microsoft XNA Framework Redistributable 4.0 Refresh - (.Microsoft Corporation.) [HKLM][64Bits] -- {D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F} ©
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {FE23D063-934D-4829-A0D8-00634CE79B4A} ©
O42 - Logiciel: Gerenciador de Downloads - (.Level Up! Gerenciador.) [HKCU][64Bits] -- a54e16f5d00985b6
O42 - Logiciel: GameRanger - (.GameRanger Technologies.) [HKCU][64Bits] -- GameRanger ©
O42 - Logiciel: Popcorn Time - (.Popcorn Official.) [HKCU][64Bits] -- Popcorn Time ©
O42 - Logiciel: DC Universe Online Live - (.Sony Online Entertainment.) [HKCU][64Bits] -- SOE-DC Universe Online Live ©
O42 - Logiciel: PlanetSide 2 - (.Sony Online Entertainment.) [HKCU][64Bits] -- SOE-PlanetSide 2 ©
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU][64Bits] -- Spotify ©
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent

---\\ Ponto de restauro do sistema (150) - 13s
HKLM\SOFTWARE\Wow6432Node\2K Games
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AdwCleaner
HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies
HKLM\SOFTWARE\Wow6432Node\Apple Inc.
HKLM\SOFTWARE\Wow6432Node\AVAST Software
HKLM\SOFTWARE\Wow6432Node\baidu
HKLM\SOFTWARE\Wow6432Node\Baidu Security
HKLM\SOFTWARE\Wow6432Node\Baidu_Drp_pos
HKLM\SOFTWARE\Wow6432Node\BandiMPEG1
HKLM\SOFTWARE\Wow6432Node\BANDISOFT
HKLM\SOFTWARE\Wow6432Node\Battlelog Web Plugins
HKLM\SOFTWARE\Wow6432Node\Bethesda Softworks
HKLM\SOFTWARE\Wow6432Node\BlueStacks
HKLM\SOFTWARE\Wow6432Node\bohemia interactive
HKLM\SOFTWARE\Wow6432Node\c9c672a5-13f3-4398-ba72-7f2ddb200ee1 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\CDDB
HKLM\SOFTWARE\Wow6432Node\CloudOpt
HKLM\SOFTWARE\Wow6432Node\CLSID
HKLM\SOFTWARE\Wow6432Node\Disc Soft
HKLM\SOFTWARE\Wow6432Node\DSPRobotics
HKLM\SOFTWARE\Wow6432Node\Dxtory Software
HKLM\SOFTWARE\Wow6432Node\e4fad717-b28e-429a-ba31-c0165b8e5f8f =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\EasyAntiCheat
HKLM\SOFTWARE\Wow6432Node\Electronic Arts
HKLM\SOFTWARE\Wow6432Node\Fraps
HKLM\SOFTWARE\Wow6432Node\GamersFirst
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\GSC Game World
HKLM\SOFTWARE\Wow6432Node\Hi-Rez Studios
HKLM\SOFTWARE\Wow6432Node\HiRez Studios
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\Image-Line
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\IObit
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\LogMeIn Hamachi
HKLM\SOFTWARE\Wow6432Node\LOOT
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\NAMCO BANDAI Games
HKLM\SOFTWARE\Wow6432Node\Novacore Studios
HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\Origin
HKLM\SOFTWARE\Wow6432Node\Origin Games
HKLM\SOFTWARE\Wow6432Node\Propellerhead Software
HKLM\SOFTWARE\Wow6432Node\re-logic
HKLM\SOFTWARE\Wow6432Node\Red 5 Studios
HKLM\SOFTWARE\Wow6432Node\Rockstar Games
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\SmartSaver+ 15 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SmartSaver+ 15-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Software by Design
HKLM\SOFTWARE\Wow6432Node\Sony Creative Software
HKLM\SOFTWARE\Wow6432Node\THQ
HKLM\SOFTWARE\Wow6432Node\TP-LINK
HKLM\SOFTWARE\Wow6432Node\Tunngle.net
HKLM\SOFTWARE\Wow6432Node\Ubisoft
HKLM\SOFTWARE\Wow6432Node\us army
HKLM\SOFTWARE\Wow6432Node\Valve
HKLM\SOFTWARE\Wow6432Node\WB Games
HKLM\SOFTWARE\Wow6432Node\WBGames
HKLM\SOFTWARE\Wow6432Node\WinRAR
HKLM\SOFTWARE\Wow6432Node\Xiph.Org
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\4A-Games
HKCU\SOFTWARE\7-Zip
HKCU\SOFTWARE\AVAST Software
HKCU\SOFTWARE\Baidu
HKCU\SOFTWARE\Baidu Security
HKCU\SOFTWARE\BandiMPEG1
HKCU\SOFTWARE\BANDISOFT
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Bohemia Interactive
HKCU\SOFTWARE\Cheat Engine
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\Cryptic
HKCU\SOFTWARE\Deep Silver
HKCU\SOFTWARE\Digital Extremes
HKCU\SOFTWARE\DirectShow
HKCU\SOFTWARE\Disc Soft
HKCU\SOFTWARE\Dodge Roll
HKCU\SOFTWARE\Drivers
HKCU\SOFTWARE\Dry Cactus
HKCU\SOFTWARE\Eat Create Sleep
HKCU\SOFTWARE\Electronic Arts
HKCU\SOFTWARE\Facebook
HKCU\SOFTWARE\FixKorea
HKCU\SOFTWARE\FLT
HKCU\SOFTWARE\Freejam
HKCU\SOFTWARE\GameRanger
HKCU\SOFTWARE\HngSync
HKCU\SOFTWARE\Hoplon
HKCU\SOFTWARE\Hyper Hippo Productions Ltd.
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\Image-Line
HKCU\SOFTWARE\IndieGala
HKCU\SOFTWARE\Inplay
HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\L2j Community Network
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Logitech
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\MAIET Entertainment
HKCU\SOFTWARE\MakeMSI
HKCU\SOFTWARE\MC4D
HKCU\SOFTWARE\MCAFEE
HKCU\SOFTWARE\Mirillis
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Oracle
HKCU\SOFTWARE\osu!
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Red 5 Studios
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Rocketeer Games Studio
HKCU\SOFTWARE\SecuROM
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Smartly Dressed Games
HKCU\SOFTWARE\Software by Design
HKCU\SOFTWARE\Sony Creative Software
HKCU\SOFTWARE\Spotify
HKCU\SOFTWARE\SUPERHOT beta
HKCU\SOFTWARE\Sysinternals
HKCU\SOFTWARE\System32
HKCU\SOFTWARE\SYSTEMAX Software Development
HKCU\SOFTWARE\Tribo Gamer
HKCU\SOFTWARE\Trion
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\Tunngle.net
HKCU\SOFTWARE\Ubisoft
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\US Army
HKCU\SOFTWARE\Valve
HKCU\SOFTWARE\VirtualDub.org
HKCU\SOFTWARE\Win
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\ZD Soft
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\Zero Point Software

---\\ Conteúdo das pastas Programs (303) - 13s
O43 - CFD: 2015/06/25 16:42:41 - [] D -- C:\Program Files (x86)\1-click run
O43 - CFD: 2015/04/29 00:00:26 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2015/07/07 23:36:34 - [] D -- C:\Program Files (x86)\Audacity
O43 - CFD: 2014/11/12 10:02:39 - [] D -- C:\Program Files (x86)\baidu
O43 - CFD: 2015/10/25 13:30:56 - [] D -- C:\Program Files (x86)\Baidu Security
O43 - CFD: 2015/01/16 12:13:05 - [] D -- C:\Program Files (x86)\Bandicam
O43 - CFD: 2015/01/16 12:13:01 - [] D -- C:\Program Files (x86)\BandiMPEG1
O43 - CFD: 2015/10/25 14:20:38 - [] D -- C:\Program Files (x86)\BlueStacks
O43 - CFD: 2015/08/15 21:46:13 - [] D -- C:\Program Files (x86)\Bonjour
O43 - CFD: 2015/10/25 13:55:49 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/07/01 19:15:48 - [] D -- C:\Program Files (x86)\CW
O43 - CFD: 2014/10/23 19:48:19 - [] D -- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 2015/03/05 12:08:47 - [] D -- C:\Program Files (x86)\DSPRobotics
O43 - CFD: 2015/02/11 20:37:02 - [] D -- C:\Program Files (x86)\Eddie Sekiguchi Softwares
O43 - CFD: 2015/07/08 01:28:16 - [] D -- C:\Program Files (x86)\ExKode
O43 - CFD: 2014/11/05 07:08:03 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2015/10/24 21:21:08 - [] D -- C:\Program Files (x86)\Image-Line
O43 - CFD: 2015/10/16 01:07:29 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/05/02 14:27:00 - [] D -- C:\Program Files (x86)\Java
O43 - CFD: 2015/08/22 23:40:09 - [] D -- C:\Program Files (x86)\LogMeIn Hamachi
O43 - CFD: 2015/05/28 23:13:50 - [] D -- C:\Program Files (x86)\LOOT
O43 - CFD: 2015/09/21 00:36:30 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2014/11/04 19:21:52 - [] D -- C:\Program Files (x86)\Microsoft Chart Controls
O43 - CFD: 2015/09/21 00:40:15 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2015/09/21 00:40:12 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 2015/09/21 00:40:12 - [] D -- C:\Program Files (x86)\Microsoft Sync Framework
O43 - CFD: 2015/09/21 00:40:59 - [] D -- C:\Program Files (x86)\Microsoft Synchronization Services
O43 - CFD: 2015/09/21 00:37:44 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD: 2014/11/19 11:15:49 - [] D -- C:\Program Files (x86)\Microsoft XNA
O43 - CFD: 2015/09/21 00:40:12 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/10/16 10:55:40 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 2015/10/16 10:55:40 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 2015/09/21 00:42:28 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2015/09/06 12:22:54 - [] D -- C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD: 2014/10/21 11:42:45 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/10/14 17:56:18 - [] RD -- C:\Program Files (x86)\Skype
O43 - CFD: 2015/09/23 19:30:43 - [] D -- C:\Program Files (x86)\Software by Design
O43 - CFD: 2015/01/15 23:04:24 - [] D -- C:\Program Files (x86)\Sony
O43 - CFD: 2015/10/25 14:44:52 - [] D -- C:\Program Files (x86)\Steam
O43 - CFD: 2015/03/05 12:09:22 - [] D -- C:\Program Files (x86)\VstPlugins
O43 - CFD: 2015/08/15 02:17:18 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2015/03/17 13:29:59 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2015/03/17 13:29:59 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2015/03/17 13:29:59 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 2013/08/22 13:36:30 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2015/03/17 13:29:59 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2015/03/17 13:29:59 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2013/08/22 13:36:30 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2013/08/22 13:36:30 - [] D -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 2014/10/21 20:38:00 - [] D -- C:\Program Files (x86)\WinRAR
O43 - CFD: 2015/09/06 10:22:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games
O43 - CFD: 2015/10/24 14:57:09 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
O43 - CFD: 2015/03/17 13:32:47 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/10/25 14:04:35 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/06/10 01:42:21 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/10/23 09:28:51 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
O43 - CFD: 2014/12/17 00:34:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu Browser
O43 - CFD: 2014/11/05 07:25:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Batman Arkham Origins
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BioShock Infinite
O43 - CFD: 2015/08/13 19:19:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
O43 - CFD: 2014/10/30 07:50:22 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 2015/10/24 17:35:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter Strike 1.6 - 2013
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6
O43 - CFD: 2014/10/23 19:48:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
O43 - CFD: 2015/05/12 19:50:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dust An Elysian Tail
O43 - CFD: 2015/07/21 20:16:25 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout Mod Manager
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
O43 - CFD: 2015/03/06 20:29:36 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2014/11/05 07:08:12 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
O43 - CFD: 2015/03/05 12:08:59 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
O43 - CFD: 2015/05/02 13:44:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2014/12/11 07:48:01 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Level Up! Games
O43 - CFD: 2015/08/22 23:40:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
O43 - CFD: 2015/10/24 17:35:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOOT
O43 - CFD: 2013/08/22 13:36:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
O43 - CFD: 2015/09/21 00:43:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2015/05/03 16:44:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Xbox 360 Accessories
O43 - CFD: 2014/11/08 20:45:59 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
O43 - CFD: 2014/10/23 23:07:45 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
O43 - CFD: 2015/09/06 12:38:36 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
O43 - CFD: 2015/08/15 21:42:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
O43 - CFD: 2015/02/11 20:37:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PaintTool SAI
O43 - CFD: 2015/10/24 17:35:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Patch v23
O43 - CFD: 2015/03/06 20:31:43 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
O43 - CFD: 2015/05/28 20:10:32 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
O43 - CFD: 2014/10/28 20:40:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
O43 - CFD: 2015/09/21 00:43:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
O43 - CFD: 2015/09/07 09:10:36 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skyrim Update 13
O43 - CFD: 2015/01/15 23:04:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
O43 - CFD: 2015/10/01 15:14:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2015/10/25 10:25:56 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
O43 - CFD: 2015/03/17 13:32:48 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2013/09/30 01:59:41 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/10/24 17:35:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\This War of Mine
O43 - CFD: 2015/09/04 15:09:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
O43 - CFD: 2015/10/24 22:19:59 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
O43 - CFD: 2015/10/24 17:35:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Watch_Dogs
O43 - CFD: 2014/10/21 11:11:11 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2014/11/05 19:59:49 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiph.Org
O43 - CFD: 2014/11/01 11:33:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZD Soft
O43 - CFD: 2015/07/01 01:09:16 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2013/08/22 12:45:52 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2014/10/20 18:10:33 - [] D -- C:\ProgramData\AVAST Software
O43 - CFD: 2015/10/25 14:32:54 - [] D -- C:\ProgramData\Baidu
O43 - CFD: 2015/10/25 13:30:36 - [0] D -- C:\ProgramData\Baidu Security
O43 - CFD: 2015/10/25 14:22:32 - [0] D -- C:\ProgramData\BlueStacksSetup
O43 - CFD: 2014/10/21 03:31:04 - [0] SHD -- C:\ProgramData\Dados de Aplicativos
O43 - CFD: 2013/08/22 12:45:52 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2014/10/21 03:31:04 - [0] SHD -- C:\ProgramData\Documentos
O43 - CFD: 2013/08/22 12:45:52 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/10/25 13:34:04 - [] D -- C:\ProgramData\IObit
O43 - CFD: 2014/12/14 17:33:11 - [] D -- C:\ProgramData\LogMeIn
O43 - CFD: 2014/10/21 03:31:04 - [0] SHD -- C:\ProgramData\Menu Iniciar
O43 - CFD: 2015/09/21 00:40:13 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/09/21 01:08:04 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2014/10/21 03:31:04 - [0] SHD -- C:\ProgramData\Modelos
O43 - CFD: 2014/11/06 08:31:17 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2015/10/24 10:43:00 - [] D -- C:\ProgramData\NVIDIA
O43 - CFD: 2015/08/30 11:51:25 - [] D -- C:\ProgramData\NVIDIA Corporation
O43 - CFD: 2015/06/16 19:31:23 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2015/03/17 13:29:58 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2014/10/28 20:47:39 - [] SHD -- C:\ProgramData\SecuROM
O43 - CFD: 2015/09/07 09:10:58 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2015/01/15 23:04:24 - [] D -- C:\ProgramData\Sony
O43 - CFD: 2013/08/22 12:45:52 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2014/11/08 11:09:37 - [] D -- C:\ProgramData\Steam
O43 - CFD: 2014/10/21 11:47:28 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2013/08/22 12:45:52 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2014/10/21 03:40:00 - [] D -- C:\ProgramData\TP-LINK
O43 - CFD: 2015/07/01 01:09:16 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2015/04/28 23:59:18 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 2015/10/22 23:30:41 - [] D -- C:\Program Files (x86)\Common Files\AV
O43 - CFD: 2015/09/21 00:40:55 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 2015/05/02 13:31:00 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 2015/09/21 00:57:30 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 2013/08/22 13:36:33 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2015/09/07 09:10:31 - [] D -- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 2015/10/23 08:42:02 - [] D -- C:\Program Files (x86)\Common Files\Steam
O43 - CFD: 2015/09/21 01:05:22 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2014/10/23 19:40:02 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
O43 - CFD: 2015/07/29 10:29:27 - [] D -- C:\Users\Mario\AppData\Roaming\.Feed the beast
O43 - CFD: 2015/10/24 16:51:32 - [] D -- C:\Users\Mario\AppData\Roaming\.minecraft
O43 - CFD: 2014/10/27 11:52:40 - [] D -- C:\Users\Mario\AppData\Roaming\.mono
O43 - CFD: 2015/01/30 15:57:25 - [] D -- C:\Users\Mario\AppData\Roaming\.technic
O43 - CFD: 2014/12/22 23:24:59 - [] D -- C:\Users\Mario\AppData\Roaming\11bitstudios
O43 - CFD: 2015/07/01 01:09:16 - [] D -- C:\Users\Mario\AppData\Roaming\Adobe
O43 - CFD: 2015/08/15 21:46:40 - [] D -- C:\Users\Mario\AppData\Roaming\Andy
O43 - CFD: 2015/07/06 12:16:37 - [] RD -- C:\Users\Mario\AppData\Roaming\Andy_44_Online
O43 - CFD: 2015/07/28 23:41:57 - [] D -- C:\Users\Mario\AppData\Roaming\assets
O43 - CFD: 2015/07/07 23:37:20 - [] D -- C:\Users\Mario\AppData\Roaming\Audacity
O43 - CFD: 2014/10/20 18:13:52 - [] D -- C:\Users\Mario\AppData\Roaming\AVAST Software
O43 - CFD: 2015/10/25 13:29:08 - [] D -- C:\Users\Mario\AppData\Roaming\Baidu
O43 - CFD: 2015/03/06 20:52:24 - [] D -- C:\Users\Mario\AppData\Roaming\Baidu Security
O43 - CFD: 2014/11/05 07:26:05 - [] D -- C:\Users\Mario\AppData\Roaming\BANDISOFT
O43 - CFD: 2015/06/20 15:44:50 - [] D -- C:\Users\Mario\AppData\Roaming\com.playsaurus.heroclicker
O43 - CFD: 2015/07/31 22:51:12 - [] D -- C:\Users\Mario\AppData\Roaming\config
O43 - CFD: 2015/10/22 22:16:53 - [] D -- C:\Users\Mario\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 2014/11/23 19:00:24 - [] D -- C:\Users\Mario\AppData\Roaming\Dark Souls 2
O43 - CFD: 2015/10/15 08:13:14 - [] D -- C:\Users\Mario\AppData\Roaming\DarkSoulsII
O43 - CFD: 2015/03/05 12:08:48 - [] D -- C:\Users\Mario\AppData\Roaming\FlowStone
O43 - CFD: 2015/07/28 23:50:47 - [] D -- C:\Users\Mario\AppData\Roaming\FTBInfinity
O43 - CFD: 2014/11/05 18:37:27 - [] D -- C:\Users\Mario\AppData\Roaming\ftblauncher
O43 - CFD: 2015/09/07 15:26:05 - [] D -- C:\Users\Mario\AppData\Roaming\GameRanger
O43 - CFD: 2015/01/16 13:13:01 - [] D -- C:\Users\Mario\AppData\Roaming\HandBrake
O43 - CFD: 2015/04/19 20:44:43 - [] D -- C:\Users\Mario\AppData\Roaming\HeroesAndGeneralsDesktop
O43 - CFD: 2015/03/17 19:10:08 - [] D -- C:\Users\Mario\AppData\Roaming\Identities
O43 - CFD: 2015/03/05 12:09:13 - [] D -- C:\Users\Mario\AppData\Roaming\Image-Line
O43 - CFD: 2014/10/22 09:09:25 - [] D -- C:\Users\Mario\AppData\Roaming\java
O43 - CFD: 2015/07/28 23:41:13 - [] D -- C:\Users\Mario\AppData\Roaming\libraries
O43 - CFD: 2014/10/21 10:59:01 - [] D -- C:\Users\Mario\AppData\Roaming\Macromedia
O43 - CFD: 2015/07/31 15:30:37 - [] D -- C:\Users\Mario\AppData\Roaming\MAXON
O43 - CFD: 2015/09/22 20:29:06 - [] SD -- C:\Users\Mario\AppData\Roaming\Microsoft
O43 - CFD: 2014/11/08 20:51:59 - [] D -- C:\Users\Mario\AppData\Roaming\Mirillis
O43 - CFD: 2015/05/02 14:03:13 - [] D -- C:\Users\Mario\AppData\Roaming\MoboMarket
O43 - CFD: 2015/05/02 14:03:13 - [0] D -- C:\Users\Mario\AppData\Roaming\MoboMarketUsbDriver
O43 - CFD: 2014/11/06 08:31:28 - [] D -- C:\Users\Mario\AppData\Roaming\Mozilla
O43 - CFD: 2014/10/21 22:25:40 - [] D -- C:\Users\Mario\AppData\Roaming\NVIDIA
O43 - CFD: 2014/10/22 09:08:40 - [] D -- C:\Users\Mario\AppData\Roaming\Oracle
O43 - CFD: 2014/11/06 08:17:39 - [] D -- C:\Users\Mario\AppData\Roaming\Origin
O43 - CFD: 2015/01/15 23:07:32 - [0] D -- C:\Users\Mario\AppData\Roaming\Publish Providers
O43 - CFD: 2015/05/08 22:42:05 - [] D -- C:\Users\Mario\AppData\Roaming\PunkBuster
O43 - CFD: 2014/10/28 15:24:40 - [] RHD -- C:\Users\Mario\AppData\Roaming\SecuROM
O43 - CFD: 2015/06/10 22:42:39 - [] D -- C:\Users\Mario\AppData\Roaming\Shooter
O43 - CFD: 2015/10/24 16:52:52 - [] D -- C:\Users\Mario\AppData\Roaming\Skype
O43 - CFD: 2015/07/02 22:27:14 - [] D -- C:\Users\Mario\AppData\Roaming\SmartSteamEmu
O43 - CFD: 2015/10/24 16:52:53 - [] D -- C:\Users\Mario\AppData\Roaming\Sony
O43 - CFD: 2015/01/16 15:07:37 - [] D -- C:\Users\Mario\AppData\Roaming\Sony Creative Software Inc
O43 - CFD: 2015/10/25 15:15:35 - [] D -- C:\Users\Mario\AppData\Roaming\Spotify
O43 - CFD: 2015/07/22 20:56:56 - [] D -- C:\Users\Mario\AppData\Roaming\Steam
O43 - CFD: 2014/11/25 18:16:08 - [] D -- C:\Users\Mario\AppData\Roaming\StunlockStudios
O43 - CFD: 2015/02/11 20:29:59 - [] D -- C:\Users\Mario\AppData\Roaming\SYSTEMAX Software Development
O43 - CFD: 2015/10/07 00:28:34 - [] D -- C:\Users\Mario\AppData\Roaming\Tap_Dungeon
O43 - CFD: 2014/10/27 15:20:05 - [] D -- C:\Users\Mario\AppData\Roaming\theHunter
O43 - CFD: 2014/10/27 15:18:39 - [] D -- C:\Users\Mario\AppData\Roaming\theHunterSteam
O43 - CFD: 2015/07/28 11:41:18 - [] D -- C:\Users\Mario\AppData\Roaming\Trove
O43 - CFD: 2015/09/05 10:21:41 - [] D -- C:\Users\Mario\AppData\Roaming\Tunngle
O43 - CFD: 2014/11/15 13:06:57 - [] D -- C:\Users\Mario\AppData\Roaming\Unity
O43 - CFD: 2015/10/24 17:35:27 - [] D -- C:\Users\Mario\AppData\Roaming\uTorrent
O43 - CFD: 2015/07/28 23:38:07 - [] D -- C:\Users\Mario\AppData\Roaming\versions
O43 - CFD: 2014/10/21 11:11:41 - [] D -- C:\Users\Mario\AppData\Roaming\WinRAR
O43 - CFD: 2015/04/14 22:23:05 - [] D -- C:\Users\Mario\AppData\Roaming\WizardWars
O43 - CFD: 2014/11/01 11:34:11 - [] D -- C:\Users\Mario\AppData\Roaming\ZD Soft
O43 - CFD: 2015/10/25 15:15:39 - [] D -- C:\Users\Mario\AppData\Roaming\ZHP
O43 - CFD: 2015/10/24 16:46:55 - [0] D -- C:\Users\Mario\AppData\Roaming\zxTorrent
O43 - CFD: 2014/11/15 22:09:17 - [] D -- C:\Users\Mario\AppData\Local\4A Games
O43 - CFD: 2015/07/01 22:14:45 - [] D -- C:\Users\Mario\AppData\Local\Adobe
O43 - CFD: 2014/11/05 07:07:22 - [] D -- C:\Users\Mario\AppData\Local\Apps
O43 - CFD: 2014/10/25 17:14:37 - [] D -- C:\Users\Mario\AppData\Local\Arma 3
O43 - CFD: 2014/10/23 23:07:58 - [] D -- C:\Users\Mario\AppData\Local\Black_Tree_Gaming
O43 - CFD: 2015/08/13 19:18:23 - [] D -- C:\Users\Mario\AppData\Local\Bluestacks
O43 - CFD: 2015/07/03 23:26:00 - [] D -- C:\Users\Mario\AppData\Local\CEF
O43 - CFD: 2014/10/25 18:15:08 - [] D -- C:\Users\Mario\AppData\Local\Chromium
O43 - CFD: 2014/10/25 23:10:16 - [] D -- C:\Users\Mario\AppData\Local\CrashRpt =>.Superfluous.CrashReports
O43 - CFD: 2014/10/21 03:31:54 - [0] SHD -- C:\Users\Mario\AppData\Local\Dados de Aplicativos
O43 - CFD: 2015/09/04 16:21:24 - [] D -- C:\Users\Mario\AppData\Local\Darksiders2
O43 - CFD: 2014/11/18 18:46:15 - [0] D -- C:\Users\Mario\AppData\Local\Deployment
O43 - CFD: 2015/10/16 13:29:02 - [0] D -- C:\Users\Mario\AppData\Local\Diagnostics
O43 - CFD: 2015/07/08 01:42:48 - [] D -- C:\Users\Mario\AppData\Local\Dxtory Software
O43 - CFD: 2014/10/30 10:53:56 - [] D -- C:\Users\Mario\AppData\Local\EdgeOfReality
O43 - CFD: 2015/09/23 20:06:42 - [] D -- C:\Users\Mario\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2015/06/21 21:58:38 - [0] SHD -- C:\Users\Mario\AppData\Local\EmieBrowserModeList
O43 - CFD: 2015/06/21 21:58:38 - [0] SHD -- C:\Users\Mario\AppData\Local\EmieSiteList
O43 - CFD: 2015/06/21 21:58:38 - [0] SHD -- C:\Users\Mario\AppData\Local\EmieUserList
O43 - CFD: 2014/11/20 20:35:26 - [] D -- C:\Users\Mario\AppData\Local\ESN
O43 - CFD: 2014/12/15 15:09:43 - [] D -- C:\Users\Mario\AppData\Local\Facebook
O43 - CFD: 2014/11/10 10:41:38 - [] D -- C:\Users\Mario\AppData\Local\FalloutNV
O43 - CFD: 2015/03/16 23:59:15 - [] D -- C:\Users\Mario\AppData\Local\FOMM
O43 - CFD: 2014/11/07 09:48:02 - [] D -- C:\Users\Mario\AppData\Local\ftblauncher
O43 - CFD: 2014/10/20 18:06:39 - [] D -- C:\Users\Mario\AppData\Local\Google
O43 - CFD: 2014/10/21 03:31:54 - [0] SHD -- C:\Users\Mario\AppData\Local\Histórico
O43 - CFD: 2014/10/23 11:48:48 - [] D -- C:\Users\Mario\AppData\Local\IsolatedStorage
O43 - CFD: 2014/12/14 17:33:11 - [] D -- C:\Users\Mario\AppData\Local\LogMeIn
O43 - CFD: 2015/10/25 14:20:05 - [] D -- C:\Users\Mario\AppData\Local\LogMeIn Hamachi
O43 - CFD: 2015/10/14 15:32:47 - [] D -- C:\Users\Mario\AppData\Local\LOOT
O43 - CFD: 2014/11/06 21:17:30 - [] D -- C:\Users\Mario\AppData\Local\Macromedia
O43 - CFD: 2015/10/01 15:32:39 - [] D -- C:\Users\Mario\AppData\Local\Microsoft
O43 - CFD: 2015/10/24 16:51:31 - [0] D -- C:\Users\Mario\AppData\Local\Microsoft Help
O43 - CFD: 2014/11/12 10:01:09 - [] D -- C:\Users\Mario\AppData\Local\MiniService
O43 - CFD: 2014/11/08 20:52:00 - [] D -- C:\Users\Mario\AppData\Local\Mirillis
O43 - CFD: 2014/11/06 08:31:29 - [] D -- C:\Users\Mario\AppData\Local\Mozilla
O43 - CFD: 2014/12/13 00:40:30 - [] D -- C:\Users\Mario\AppData\Local\NBGI
O43 - CFD: 2014/10/20 18:02:57 - [] D -- C:\Users\Mario\AppData\Local\NVIDIA
O43 - CFD: 2015/07/21 20:34:59 - [] D -- C:\Users\Mario\AppData\Local\NVIDIA Corporation
O43 - CFD: 2015/03/31 20:04:41 - [] D -- C:\Users\Mario\AppData\Local\openvr
O43 - CFD: 2014/11/20 20:35:35 - [] D -- C:\Users\Mario\AppData\Local\Origin
O43 - CFD: 2015/08/06 20:05:54 - [] D -- C:\Users\Mario\AppData\Local\Packages
O43 - CFD: 2014/11/18 08:54:40 - [0] D -- C:\Users\Mario\AppData\Local\PointBlank
O43 - CFD: 2015/05/10 21:48:20 - [] D -- C:\Users\Mario\AppData\Local\Popcorn Time
O43 - CFD: 2015/08/29 17:44:27 - [] D -- C:\Users\Mario\AppData\Local\Popcorn-Time
O43 - CFD: 2014/10/21 03:34:15 - [] D -- C:\Users\Mario\AppData\Local\Programs
O43 - CFD: 2014/11/20 20:40:01 - [] D -- C:\Users\Mario\AppData\Local\PunkBuster
O43 - CFD: 2014/11/05 20:00:13 - [] D -- C:\Users\Mario\AppData\Local\Red 5 Studios
O43 - CFD: 2014/10/28 20:40:08 - [] D -- C:\Users\Mario\AppData\Local\Rockstar Games
O43 - CFD: 2014/10/27 16:46:51 - [] D -- C:\Users\Mario\AppData\Local\SCE
O43 - CFD: 2015/04/26 11:46:17 - [] D -- C:\Users\Mario\AppData\Local\Self_Updater
O43 - CFD: 2015/09/24 19:21:43 - [] D -- C:\Users\Mario\AppData\Local\Setup Integrity Check
O43 - CFD: 2015/09/04 15:11:29 - [] D -- C:\Users\Mario\AppData\Local\SKIDROW
O43 - CFD: 2014/12/13 23:52:55 - [] D -- C:\Users\Mario\AppData\Local\Skype
O43 - CFD: 2015/10/14 15:34:48 - [] D -- C:\Users\Mario\AppData\Local\Skyrim
O43 - CFD: 2015/01/15 23:07:24 - [] D -- C:\Users\Mario\AppData\Local\Sony
O43 - CFD: 2015/10/25 15:10:38 - [] D -- C:\Users\Mario\AppData\Local\Spotify
O43 - CFD: 2015/09/30 11:43:50 - [] D -- C:\Users\Mario\AppData\Local\Steam
O43 - CFD: 2015/09/30 13:12:21 - [] D -- C:\Users\Mario\AppData\Local\storage
O43 - CFD: 2015/10/25 15:15:07 - [] D -- C:\Users\Mario\AppData\Local\Temp
O43 - CFD: 2014/10/21 03:31:54 - [0] SHD -- C:\Users\Mario\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/05/15 00:24:49 - [] D -- C:\Users\Mario\AppData\Local\TERA
O43 - CFD: 2014/10/27 15:20:04 - [] D -- C:\Users\Mario\AppData\Local\theHunter
O43 - CFD: 2015/04/26 11:46:26 - [] D -- C:\Users\Mario\AppData\Local\ToonHUD
O43 - CFD: 2014/10/21 11:44:43 - [] D -- C:\Users\Mario\AppData\Local\Ubisoft
O43 - CFD: 2015/05/08 22:49:07 - [] D -- C:\Users\Mario\AppData\Local\Ubisoft Game Launcher
O43 - CFD: 2014/11/15 13:01:39 - [] D -- C:\Users\Mario\AppData\Local\Unity
O43 - CFD: 2015/01/16 12:07:07 - [] D -- C:\Users\Mario\AppData\Local\VirtualStore
O43 - CFD: 2015/10/24 16:51:10 - [] D -- C:\Users\Mario\AppData\Local\Warframe
O43 - CFD: 2015/06/25 16:42:46 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
O43 - CFD: 2013/08/22 13:36:32 - [] RD -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2013/08/22 13:36:32 - [] RD -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/10/16 11:01:36 - [] RD -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/08/21 22:00:42 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy
O43 - CFD: 2015/07/17 20:07:41 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu MoboMarket
O43 - CFD: 2015/06/25 21:04:58 - [0] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6
O43 - CFD: 2015/01/16 13:09:54 - [0] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake
O43 - CFD: 2014/12/11 07:48:46 - [0] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hoplon
O43 - CFD: 2015/10/24 22:19:59 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
O43 - CFD: 2015/10/24 17:35:23 - [0] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IVMP
O43 - CFD: 2014/11/18 10:44:55 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Level Up! Gerenciador
O43 - CFD: 2013/08/22 13:36:32 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/05/10 21:48:20 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
O43 - CFD: 2015/06/25 16:42:46 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portable Programs
O43 - CFD: 2015/05/28 21:46:09 - [0] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skyrim Update 13
O43 - CFD: 2015/09/23 19:31:35 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Software by Design
O43 - CFD: 2015/10/24 17:35:23 - [] RD -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/10/24 15:42:23 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
O43 - CFD: 2015/10/24 17:35:23 - [] RD -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2014/10/21 11:11:11 - [] D -- C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ Softwares de proteçao do sistema (Supérfluo) (6) - 0s
O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: avast [00avast] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - avast! Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll ©

---\\ Lista dos drivers do sistema (56) - 10s
O58 - SDL:2013/08/22 10:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [108896] ©
O58 - SDL:2013/08/22 10:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [782176] ©
O58 - SDL:2013/08/22 10:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79200] ©
O58 - SDL:2013/08/22 10:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] ©
O58 - SDL:2013/08/22 10:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [25952] ©
O58 - SDL:2013/08/22 10:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [114016] ©
O58 - SDL:2015/10/22 22:58:21 A . (.AVAST Software - avast! HWID.) -- C:\Windows\System32\drivers\aswHwid.sys [28656] ©
O58 - SDL:2015/10/22 22:58:21 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\Windows\System32\drivers\aswMonFlt.sys [90968] ©
O58 - SDL:2015/10/22 22:58:20 A . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\Windows\System32\drivers\aswRdr2.sys [93528] ©
O58 - SDL:2015/10/22 22:58:21 A . (.AVAST Software - avast! Revert.) -- C:\Windows\System32\drivers\aswRvrt.sys [65224] ©
O58 - SDL:2015/10/22 22:58:10 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\drivers\aswSnx.sys [1049880] ©
O58 - SDL:2015/10/22 22:58:21 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\aswSP.sys [448968] ©
O58 - SDL:2015/10/22 22:58:21 A . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\drivers\aswStm.sys [153744] ©
O58 - SDL:2015/10/22 22:58:21 A . (.AVAST Software - avast! VM Monitor.) -- C:\Windows\System32\drivers\aswVmm.sys [274808] ©
O58 - SDL:2013/08/12 08:57:54 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros USB Wireless LAN device dr.) -- C:\Windows\System32\drivers\athuw8x.sys [2919936] ©
O58 - SDL:2013/08/12 21:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [17624] ©
O58 - SDL:2013/08/22 10:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [531296] ©
O58 - SDL:2014/10/30 19:39:28 A . (.ClickCaption - Click Caption Driver x64.) -- C:\Windows\System32\drivers\ccnfd_1_10_0_2.sys [58232] =>PUP.Optional.ClickCaption
O58 - SDL:2014/10/23 19:48:19 A . (.Disc Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\drivers\dtsoftbus01.sys [283064] ©
O58 - SDL:2013/08/22 10:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3357024] ©
O58 - SDL:2015/08/03 13:12:32 AH . (.LogMeIn Inc. - LogMeIn Hamachi Virtual Miniport Driver.) -- C:\Windows\System32\drivers\Hamdrv.sys [45680] ©
O58 - SDL:2013/08/22 10:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] ©
O58 - SDL:2013/07/30 16:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568] ©
O58 - SDL:2013/07/25 17:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320] ©
O58 - SDL:2013/08/09 22:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [651248] ©
O58 - SDL:2013/08/22 10:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] ©
O58 - SDL:2013/08/22 10:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [109408] ©
O58 - SDL:2013/08/22 10:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [93536] ©
O58 - SDL:2013/08/22 10:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [81760] ©
O58 - SDL:2013/08/22 10:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] ©
O58 - SDL:2013/08/22 10:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [56672] ©
O58 - SDL:2013/08/22 10:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] ©
O58 - SDL:2013/08/22 10:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] ©
O58 - SDL:2013/06/18 16:30:32 A . (.Ralink Technology Corp. - Ralink 802.11n Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr28ux.sys [2408208] ©
O58 - SDL:2015/10/22 22:58:08 A . (.AVAST Software - avast! NG snapshot driver.) -- C:\Windows\System32\drivers\ngvss.sys [132656] ©
O58 - SDL:2015/08/25 16:46:21 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\System32\drivers\nvhda64v.sys [204648] ©
O58 - SDL:2015/08/25 16:46:21 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [11089200] ©
O58 - SDL:2013/08/22 10:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] ©
O58 - SDL:2013/08/22 10:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168288] ©
O58 - SDL:2015/08/11 02:52:30 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\Windows\System32\drivers\nvvad64v.sys [50472] ©
O58 - SDL:2015/08/25 16:46:21 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\Windows\System32\drivers\nvvadarm.sys [39032] ©
O58 - SDL:2013/06/18 12:46:17 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\Windows\System32\drivers\Rt630x64.sys [591360] ©
O58 - SDL:2013/08/22 13:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] ©
O58 - SDL:2013/08/22 10:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] ©
O58 - SDL:2013/08/22 10:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] ©
O58 - SDL:2014/01/22 09:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [108800] ©
O58 - SDL:2014/01/22 09:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [206080] ©
O58 - SDL:2013/08/22 10:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] ©
O58 - SDL:2009/09/16 08:02:42 A . (.Tunngle.net - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901t.sys [31232]
O58 - SDL:2014/10/11 14:29:02 A . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\drivers\VBoxDrv.sys [917112] ©
O58 - SDL:2014/10/11 14:27:46 A . (.Oracle Corporation - VirtualBox Host-Only Network Adapter Driver.) -- C:\Windows\System32\drivers\VBoxNetAdp.sys [142528] ©
O58 - SDL:2014/10/11 14:27:44 A . (.Oracle Corporation - VirtualBox Bridged Networking Driver.) -- C:\Windows\System32\drivers\VBoxNetFlt.sys [157448] ©
O58 - SDL:2014/10/11 14:27:44 A . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\System32\drivers\VBoxUSBMon.sys [129168] ©
O58 - SDL:2013/08/22 10:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19808] ©
O58 - SDL:2013/08/22 10:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [168800] ©
O58 - SDL:2013/08/22 10:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] ©

---\\ Últimos ficheiros alterados ou criados (Utilizador) (8) - 123s
O61 - LFC: 2015/10/19 18:15:11 A . (.Copyright (C) 2015 The Chromium Embedded Framework Au.) -- C:\Users\Mario\AppData\Roaming\Spotify\libcef.dll [50678592]
O61 - LFC: 2015/10/19 18:15:11 A . (..) -- C:\Users\Mario\AppData\Roaming\Spotify\natives_blob.bin [410849]
O61 - LFC: 2015/10/19 18:15:11 A . (..) -- C:\Users\Mario\AppData\Roaming\Spotify\snapshot_blob.bin [463444]
O61 - LFC: 2015/10/19 18:15:11 A . (..) -- C:\Users\Mario\AppData\Roaming\Spotify\wow_helper.exe [73024]
O61 - LFC: 2015/10/25 13:48:45 A . (..) -- C:\Users\Mario\AppData\Roaming\NVIDIA\GLCache\8239870e7d418e9bbb808d84805de6c1\632fbf7739ccb01c\2ad2147cf33d62a7.bin [530969]
O61 - LFC: 2015/10/21 05:01:36 A . (..) -- C:\Users\Mario\AppData\Local\NVIDIA\NvBackend\UMDShim\nvcoproc.bin [5996218]
O61 - LFC: 2015/10/23 18:52:07 A . (..) -- C:\Users\Mario\AppData\Local\NVIDIA\NvBackend\Packages\000081ae\DAO.20098633.exe [6681616]
O61 - LFC: 2015/10/21 18:46:13 A . (..) -- C:\Users\Mario\AppData\Local\NVIDIA\NvBackend\Packages\00008191\CoProc update.20084017.exe [590408]

---\\ Associações Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Copyright (C) 2011 - spark.) -- C:\Program Files (x86)\baidu\Spark\spark.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ©

---\\ Menu de inicialização Internet (16) - 1s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Copyright (C) 2011 - spark.) -- C:\Program Files (x86)\baidu\Spark\Spark.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Copyright (C) 2011 - spark.) -- C:\Program Files (x86)\baidu\Spark\spark.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Copyright (C) 2011 - spark.) -- C:\Program Files (x86)\baidu\Spark\spark.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Copyright (C) 2011 - spark.) -- C:\Program Files (x86)\baidu\Spark\spark.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe ©

---\\ Pesquisa de infeção nos navegadores da Internet (18) - 6s
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.alias", "do-search"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.iconURL", "http://do-search.com/favicon.ico"); =>PUP.Optional.DoSearches
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.name", "do-search"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.ptid", "cor"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.uid", "ST500DM002-1BD142_S2ATRZ0EXXXXS2ATRZ0E"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("browser.search.searchengine.url", "http://do-search.com/web/?type=ds&ts=1429625709&from=cor&uid=ST500DM002-1BD142_S2ATR[...] =>PUP.Optional.DoSearches
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.BrowseStudio.asul", "1415795448357"); =>PUP.Optional.BrowseStudio
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.BrowseStudio.aul", "1415796874692"); =>PUP.Optional.BrowseStudio
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.BrowseStudio.irl", true); =>PUP.Optional.BrowseStudio
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.BrowseStudio.is", "isgiwhBR"); =>PUP.Optional.BrowseStudio
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.BrowseStudio.ug", "FF801FE6-3126-47F3-B68C-6DAA1F88ECAC"); =>PUP.Optional.BrowseStudio
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.quick_searchff@gmail.com.install-event-fired", true); =>PUP.Optional.QuickSearch
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.quick_start.enable_search1", false); =>PUP.Optional.QuickStart
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); =>PUP.Optional.QuickStart
O69 - SBI: prefs.js [Mario - 5zlx3pi4.default-1415703582551] user_pref("extensions.sweetsearch@gmail.com.install-event-fired", true); =>PUP.Optional.SweetSearch
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} - (Microsoft (Bing)) - http://www.bing.com/

---\\ Listagem dos serviços iniciados pelo Svchost (36) - 2s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Serviço de Experiência com Aplicativo.) -- C:\Windows\System32\aelupsvc.dll [214528] ©
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\Windows\System32\certprop.dll [156160] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\Windows\System32\certprop.dll [156160] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\Windows\system32\srvsvc.dll [329216] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [1360896] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\ikeext.dll [1084416] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\Windows\System32\iphlpsvc.dll [926208] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\Windows\system32\seclogon.dll [31744] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\Windows\System32\appinfo.dll [110080] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\Windows\system32\iscsiexe.dll [151040] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\Windows\System32\eapsvc.dll [110592] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\Windows\system32\schedsvc.dll [1265152] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [230400] ©
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Serviço Agendador de Classes de Multimídia.) -- C:\Windows\system32\mmcss.dll [71168] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\Windows\System32\browser.dll [135168] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [228864] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho.) -- C:\Windows\System32\SessEnv.dll [339968] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\Windows\System32\wercplsupport.dll [84992] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\Windows\system32\kmsvc.dll [101376] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [348672] ©
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Serviço de Estrutura de Localização do Wind.) -- C:\Windows\System32\GeofenceMonitorService.dll [522240] ©
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\Windows\system32\wlidsvc.dll [1639424] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\Windows\system32\themeservice.dll [59392] ©
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\Windows\System32\DeviceSetupManager.dll [206848] ©
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede.) -- C:\Windows\System32\ncasvc.dll [166400] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acess.) -- C:\Windows\System32\rasauto.dll [102912] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\Windows\System32\rasmans.dll [542208] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [226816] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) -- C:\Windows\System32\sens.dll [73728] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\Windows\System32\ipnathlp.dll [452608] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft(R) Windo.) -- C:\Windows\System32\tapisrv.dll [313344] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [3705344] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) -- C:\Windows\System32\qmgr.dll [933376] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [640000] ©
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação do software.) -- C:\Windows\System32\appmgmts.dll [187904] ©
O83 - Search Svchost Services: MsKeyboardFilter (MsKeyboardFilter) . (.Microsoft Corporation - SvcHost Service for Microsoft Keyboard Filt.) -- C:\Windows\System32\KeyboardFilterSvc.dll [92992] ©

---\\ Lista das exceções do FireWall (FirewallRules) (27) - 3s
O87 - FAEL: "TCP Query User{51CB8FAE-7E1E-437D-AEB8-57984A65D338}C:\users\mario\appdata\roaming\utorrent\utorrent.exe" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\mario\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "UDP Query User{B0BE0AFA-D353-4C7C-A65F-AABCF288AE0C}C:\users\mario\appdata\roaming\utorrent\utorrent.exe" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\mario\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "{C6A0D1D0-7D8E-44C7-8469-FF990D6F7714}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\mario\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "{160AADEF-BE70-44E1-9698-FCEA63F368CB}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\mario\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "{B846FCC4-C779-47DD-94ED-6EB7CEE54505}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\GarrysMod\hl2.exe (.not file.)
O87 - FAEL: "{89649270-717A-4432-A4AD-A035EEF72281}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\GarrysMod\hl2.exe (.not file.)
O87 - FAEL: "{2239FFA2-B2A0-4E6F-9D74-28D99417A03B}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\Fistful of Frags\sdk\hl2.exe
O87 - FAEL: "{4BED5DEA-47CF-45CC-B132-9093E136AEDE}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\Fistful of Frags\sdk\hl2.exe
O87 - FAEL: "{6CA0CF06-DBAF-4B8E-B7B3-1CCD4B1A901E}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe (.not file.)
O87 - FAEL: "{3BDC53E2-E384-4421-9ED6-07B6770840BC}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe (.not file.)
O87 - FAEL: "TCP Query User{920776B0-6261-4DAD-8E6D-4928CEB159DA}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe (.not file.)
O87 - FAEL: "UDP Query User{3D24FC6D-4CA1-402E-B6B3-BC379B9A99C7}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe (.not file.)
O87 - FAEL: "{925C7722-2C34-46FC-9A08-BD31144C6D47}" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe (.not file.)
O87 - FAEL: "{B1BF9D65-E76C-4BC8-AE59-BF641EBA27AF}" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe (.not file.)
O87 - FAEL: "TCP Query User{F455630A-7F6C-480C-9215-6C63B175F549}C:\users\mario\appdata\local\popcorn time\node-webkit\popcorn time.exe" [In-None-P6-TRUE] .(...) -- C:\users\mario\appdata\local\popcorn time\node-webkit\popcorn time.exe
O87 - FAEL: "UDP Query User{CDF2F868-FE83-4D23-8189-455811FC3625}C:\users\mario\appdata\local\popcorn time\node-webkit\popcorn time.exe" [In-None-P17-TRUE] .(...) -- C:\users\mario\appdata\local\popcorn time\node-webkit\popcorn time.exe
O87 - FAEL: "{6A7868D0-6205-4412-88E6-765154665400}" [In-None-P17-TRUE] .(...) -- C:\users\mario\appdata\local\popcorn time\node-webkit\popcorn time.exe
O87 - FAEL: "{20CA80BE-D2F6-4C35-BA65-453455A6627E}" [In-None-P6-TRUE] .(...) -- C:\users\mario\appdata\local\popcorn time\node-webkit\popcorn time.exe
O87 - FAEL: "{D0657895-6422-40C8-9BEE-68E929CB9970}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II Scholar of the First Sin\Game\DarkSoulsII.exe (.not file.)
O87 - FAEL: "{F595FD25-3228-4F17-9344-C3412E70571A}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II Scholar of the First Sin\Game\DarkSoulsII.exe (.not file.)
O87 - FAEL: "{A8723706-4FE6-41B8-9D8C-8ECFAF6D5DF2}" [Out-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Baidu Security\Baidu Antivirus\BavUpdater.exe (.not file.)
O87 - FAEL: "{EA0649E1-B15D-4E99-BFD8-1C9CB7726505}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Mario\AppData\Roaming\uTorrent\uTorrent.exe
O87 - FAEL: "{30AF6366-4B8B-45D9-BD5B-B06DF570C90A}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Mario\AppData\Roaming\uTorrent\uTorrent.exe
O87 - FAEL: "TCP Query User{EC5A3887-E540-4E2C-AB9C-F3174BCAA107}C:\program files (x86)\steam\steamapps\downloading\730\csgo.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\downloading\730\csgo.exe
O87 - FAEL: "UDP Query User{91B6AD04-36DB-4BC8-AADC-9C5577A9D3EB}C:\program files (x86)\steam\steamapps\downloading\730\csgo.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\downloading\730\csgo.exe
O87 - FAEL: "{C7B7B69C-BF8A-4936-8653-A34CADF436D1}" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\downloading\730\csgo.exe
O87 - FAEL: "{3CD62CF2-1B36-496B-84EB-FDA0AD08E1C1}" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\steam\steamapps\downloading\730\csgo.exe

---\\ Serviços não Microsoft (SR=Executados, SS=Parados) (22) - 17s

SS - Demand [2015/10/24 19:06:54] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ©
SR - Auto [2015/10/22 22:58:15] [ 146600] Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe ©
SR - Demand [2015/10/22 22:58:07] [ 4048280] AvastVBox COM Service (AvastVBoxSvc) . (.Avast Software.) - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe ©
SR - Auto [2011/08/31 00:05:32] [ 462184] Serviço do Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe ©
SS - Demand [2015/06/16 23:33:14] [ 433784] BlueStacks Android Service (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe ©
SS - Auto [2015/06/16 23:33:36] [ 413304] BlueStacks Log Rotator Service (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe ©
SR - Auto [2015/07/21 21:23:32] [ 831096] BlueStacks Updater Service (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe ©
SR - Auto [2015/10/04 06:24:14] [ 1155376] NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe ©
SS - Demand [2014/11/05 07:07:40] [ 107912] Serviço do Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Demand [2014/11/05 07:07:40] [ 107912] Serviço do Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SR - Auto [2015/08/03 13:47:10] [ 2545512] LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) . (.LogMeIn Inc..) - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe ©
SR - Auto [2015/08/03 13:13:12] [ 417552] LMIGuardianSvc (LMIGuardianSvc) . (.LogMeIn, Inc..) - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe ©
SS - Demand [2015/10/15 23:34:24] [ 147624] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe ©
SR - Auto [2015/10/04 06:24:16] [ 1872688] NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe ©
SR - Auto [2015/10/04 06:24:10] [ 5568816] NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe ©
SR - Auto [2015/08/25 12:24:20] [ 937776] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe ©
SS - Auto [2015/07/09 14:14:04] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe ©
SR - Auto [2015/02/06 08:14:12] [ 84160] Baidu Spark Service (SparkSvc) . (.Baidu Inc..) - C:\Program Files (x86)\baidu\Spark\sparkservice.exe
SS - Demand [2014/11/11 02:28:52] [ 1356992] Baidu Spark Updater (SparkUpdater) . (.Baidu.com, Inc..) - C:\Program Files (x86)\baidu\SparkUpdate\Sparkupdate.exe
SS - Demand [2015/06/04 19:12:14] [ 837312] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe ©
SS - Demand [2015/08/25 12:08:20] [ 410744] NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe ©

---\\ Claves Tracing (6) - 2s
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseStudio_RASAPI32 =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseStudio_RASMANCS =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseStudio_RASAPI32 =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseStudio_RASMANCS =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32 =>PUP.Optional.Wajam
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS =>PUP.Optional.Wajam

---\\ Scâner Aditional (14) - 0s
C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\llihccomjnidgdibbpciaajkednnglpm
HKLM\SOFTWARE\Wow6432Node\c9c672a5-13f3-4398-ba72-7f2ddb200ee1 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\e4fad717-b28e-429a-ba31-c0165b8e5f8f =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SmartSaver+ 15 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SmartSaver+ 15-nv =>PUP.Optional.CrossRider
HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
C:\Users\Mario\AppData\Local\CrashRpt =>.Superfluous.CrashReports
C:\Windows\System32\drivers\ccnfd_1_10_0_2.sys =>PUP.Optional.ClickCaption
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseStudio_RASAPI32 =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseStudio_RASMANCS =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseStudio_RASAPI32 =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseStudio_RASMANCS =>PUP.Optional.BrowseStudio
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32 =>PUP.Optional.Wajam
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS =>PUP.Optional.Wajam

---\\ Informações complémentaires do módulos (11) - 0s
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowserExtensions
http://www.nicolascoolman.fr/blog =>.Superfluous.CrashReports
http://www.nicolascoolman.fr/blog =>PUP.Optional.ClickCaption
http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine
http://www.nicolascoolman.fr/pup-dosearches/ =>PUP.Optional.DoSearches
http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowseStudio
http://www.nicolascoolman.fr/blog =>PUP.Optional.QuickSearch
http://www.nicolascoolman.fr/pup-quickstart/ =>PUP.Optional.QuickStart
http://www.nicolascoolman.fr/blog =>PUP.Optional.SweetSearch
http://www.nicolascoolman.fr/pup-wajam/ =>PUP.Optional.Wajam

~ End of the scan, 32252 items in 262 seconds (1025)(0)()

Publicité


Signaler le contenu de ce document

Publicité