cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.4.5.57 Por Nicolas Coolman (2018/04/04)
~ iniciado por Pedro (Administrator) (2018/04/06 15:42:53)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Status da versão: Version OK
~ Modo: Scanner
~ Relatório: C:\Users\Pedro\Desktop\ZHPDiag.txt
~ Relatório: C:\Users\Pedro\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Inicialização do sistema: Normal (Normal boot)
Windows 10 Enterprise, 64-bit (Build 16299) =>.Microsoft Corporation


---\ Navegadores Internet (4) - 0s
~ GCIE: Google Chrome v65.0.3325.181
~ MFIE: Mozilla Firefox 33.1 (x86 pt-BR)
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.309.16299.0

---\ Informações sobre os produtos Windows (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\ Softwares de proteçao do sistema (2) - 2s
Windows Defender (Deactivate)
ESET Smart Security v10.1.219.1 (Protection)

---\ Monitoramento dos softwares (3) - 2s
~ Adobe Flash Player 29 NPAPI (Surveillance)
~ Adobe Flash Player 29 PPAPI (Surveillance)
~ Adobe Reader X (Surveillance)

---\ Softwares de partilha do PeerToPeer (P2P) (1) - 2s
~ µTorrent v3.5.1.44332 (P2P)

---\ Informações sobre o sistema (6) - 0s
~ Operating System: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8182.452 MB (68% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 750 GB (78%) free of 950 GB : OK =>.Disk Space

---\ Modo de conexão ao sistema (3) - 0s
~ Computer Name: PEDRO
~ User Name: Pedro
~ Logged in as Administrator

---\ Enumeração das unidades dos discos (1) - 0s
~ Drive C: has 750 GB free of 950 GB (System)

---\ Estado do Centro de Segurança do Windows (8) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\ Pesquisa particular de ficheiros genéricos (24) - 2s
[MD5.A77D56422C38C1F8A00D95D2D5B1675E] - 10/02/2018 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [3904296] =>.Microsoft Windows®
[MD5.731A783A36A8E69A6434D19D98B12A09] - 29/09/2017 - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [71168] =>.Microsoft Corporation
[MD5.BF3E1D9B2360C6BE4CC3094CD2DDC617] - 29/09/2017 - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) -- C:\WINDOWS\System32\Wininit.exe [359584] =>.Microsoft Windows Publisher®
[MD5.F763C0BF78809F263C2330333F45E26D] - 01/03/2018 - (.Microsoft Corporation - Internet Extensions para Win32.) -- C:\WINDOWS\System32\wininet.dll [3334144] =>.Microsoft Corporation
[MD5.D0926E8FC082646487BD159538F4D9F5] - 01/01/2018 - (.Microsoft Corporation - Aplicativo de Logon do Windows.) -- C:\WINDOWS\System32\Winlogon.exe [715776] =>.Microsoft Corporation
[MD5.4D487E7D2B047FB929BE00117C09F9EC] - 29/09/2017 - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) -- C:\WINDOWS\System32\sppcomapi.dll [414720] =>.Microsoft Corporation
[MD5.5AE3B789BC547BBBE2A876F587BE60F6] - 10/02/2018 - (.Microsoft Corporation - DLL da API de cliente DNS.) -- C:\WINDOWS\System32\dnsapi.dll [739696] =>.Microsoft Windows®
[MD5.66342F3BB289A5A370127F8385512A84] - 10/02/2018 - (.Microsoft Corporation - DLL da API de cliente DNS.) -- C:\WINDOWS\Syswow64\dnsapi.dll [597160] =>.Microsoft Windows®
[MD5.AD7B46330B55170ED706043DE88AC1A9] - 10/02/2018 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [614296] =>.Microsoft Windows®
[MD5.6191B9B2EE0E8CB957C683B9B341CC86] - 29/09/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [28568] =>.Microsoft Windows®
[MD5.9E82A95D77AC78C84BA75FF896B060BF] - 29/09/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [93184] =>.Microsoft Corporation
[MD5.6D83565C1652E80447EDEA6947FA89D7] - 29/09/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [159744] =>.Microsoft Corporation
[MD5.9910E9CFF5ECDCB225F82E72CE9DE459] - 29/09/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [151040] =>.Microsoft Corporation
[MD5.99A34FD1F6431A10D8C3BB50E170D0F2] - 29/09/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [86016] =>.Microsoft Corporation
[MD5.56FF074E50F9042FD2856AB3418F4B18] - 29/09/2017 - (.Microsoft Corporation - Driver de porta i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [105984] =>.Microsoft Corporation
[MD5.7BEC2AF23F586EFF0DB4DBF4331B0C70] - 29/09/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [214016] =>.Microsoft Corporation
[MD5.71729B1EE949E1B092CB5CB75CC63715] - 10/02/2018 - (.Microsoft Corporation - Minirdr SMB do Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [494488] =>.Microsoft Windows®
[MD5.7FC54F2AF5EC52C7AC05AD90FFC757E6] - 01/01/2018 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [316928] =>.Microsoft Corporation
[MD5.B6FDEBE8F640E9173AD2BA3F9C014195] - 10/02/2018 - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2395032] =>.Microsoft Windows®
[MD5.2E07EC2C1622F5E7B535D62DCD61F3AB] - 29/09/2017 - (.Microsoft Corporation - Driver de porta paralela.) -- C:\WINDOWS\System32\drivers\Parport.sys [98816] =>.Microsoft Corporation
[MD5.E0220BB6580D34001D4D1D133052DAA4] - 29/09/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [106496] =>.Microsoft Corporation
[MD5.DF83769C92527DB50653F8FB57D001FF] - 30/09/2017 - (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Micros.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [182784] =>.Microsoft Corporation
[MD5.571D82ABAC428D902ACA0CF60373C039] - 29/09/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [121240] =>.Microsoft Windows®
[MD5.5B27846CF4B1C21AFB3A35A8336BA02F] - 08/02/2018 - (.Microsoft Corporation - Driver de Cópia de Sombra de Volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [401304] =>.Microsoft Windows®

---\ Serviços NT não Microsoft e não desativados (10) - 1s
O23 - Service: Advanced SystemCare Service 11 (AdvancedSystemCareService11) . (.IObit - Advanced SystemCare Service.) - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe =>.IObit Information Technology®
O23 - Service: Cobian Backup 11 Requisitador de Cópia Sombra de Volume (cbVSCService11) . (.CobianSoft, Luis Cobian - Cobian Backup Gravity VSC Requester.) - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe =>.CobianSoft, Luis Cobian
O23 - Service: ESET Service (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Security\ekrn.exe =>.ESET, spol. s r.o.®
O23 - Service: Serviço do Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Service KMSELDI (Service KMSELDI) . (.@ByELDI - Service_KMS.) - C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
O23 - Service: vBox Service (SyncedTool) . (.eFolder - Sync Service.) - C:\Program Files (x86)\vBox\bin\agent_service.exe {0664CADB13C394F908C7E2BDF7114CC6}
O23 - Service: TeamViewer 13 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 13.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®
O23 - Service: TechSmith Uploader Service (TechSmith Uploader Service) . (.TechSmith Corporation - TechSmith Uploader Service.) - C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe =>.TechSmith Corporation
O23 - Service: TeraCopy Service (TeraCopyService) . (.Code Sector - TeraCopy Service.) - C:\Program Files\TeraCopy\TeraCopyService.exe =>.Code Sector®
O23 - Service: TightVNC Server (tvnserver) . (.GlavSoft LLC. - TightVNC Server.) - C:\Program Files\TightVNC\tvnserver.exe =>.GlavSoft LLC.®

---\ Serviços não Microsoft (SR=Executados, SS=Parados) (18) - 9s
SS - Demand [06/06/2011] [ 64952] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SS - Demand [13/03/2018] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [30/01/2018] [ 1056016] Advanced SystemCare Service 11 (AdvancedSystemCareService11) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe =>.IObit Information Technology®
SS - Demand [02/03/2009] [ 89600] Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\IDT\WDM\AESTSr64.exe =>.Andrea Electronics Corporation
SR - Auto [07/03/2013] [ 67584] Cobian Backup 11 Requisitador de Cópia Sombra de Volume (cbVSCService11) . (.CobianSoft, Luis Cobian.) - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe =>.CobianSoft, Luis Cobian
SR - Auto [22/03/2018] [ 2648184] ESET Service (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Security\ekrn.exe =>.ESET, spol. s r.o.®
SS - Auto [28/06/2017] [ 153168] Serviço do Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [28/06/2017] [ 153168] Serviço do Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [24/01/2018] [ 175056] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SS - Demand [26/10/2017] [ 38016] OpenVPN Service (OpenVPNService) . (.The OpenVPN Project.) - C:\Program Files\OpenVPN\bin\openvpnserv.exe =>.OpenVPN Technologies, Inc.®
SS - Demand [28/02/2013] [ 118520] Remote Packet Capture Protocol v.0 (experimental) (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe =>.Riverbed Technology, Inc.®
SR - Auto [01/12/2015] [ 743616] Service KMSELDI (Service KMSELDI) . (.@ByELDI.) - C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
SS - Demand [04/08/2010] [ 265728] @%SystemRoot%\system32\stlang64.dll,-10102 (STacSV) . (.IDT, Inc..) - C:\Program Files\IDT\WDM\stacsv64.exe =>.IDT, Inc.
SR - Auto [09/01/2018] [11729496] vBox Service (SyncedTool) . (.eFolder.) - C:\Program Files (x86)\vBox\bin\agent_service.exe {0664CADB13C394F908C7E2BDF7114CC6}
SR - Auto [09/03/2018] [11294448] TeamViewer 13 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®
SR - Auto [26/01/2015] [ 3408384] TechSmith Uploader Service (TechSmith Uploader Service) . (.TechSmith Corporation.) - C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe =>.TechSmith Corporation
SR - Auto [05/05/2017] [ 110416] TeraCopy Service (TeraCopyService) . (.Code Sector.) - C:\Program Files\TeraCopy\TeraCopyService.exe =>.Code Sector®
SR - Auto [19/07/2013] [ 2179056] TightVNC Server (tvnserver) . (.GlavSoft LLC..) - C:\Program Files\TightVNC\tvnserver.exe =>.GlavSoft LLC.®

---\ Tarefas planificadas automaticamente (Register) (170) - 3s
O38 - TASK: {0319D346-9E60-4CE2-B937-EF6C981CC0F1} [64Bits][\Microsoft\Windows\PushToInstall\Registration] - (.Microsoft Corporation - Ferramenta de Configuração do Gerenciador d.) -- C:\Windows\System32\sc.exe [69120] =>.Microsoft Corporation
O38 - TASK: {03BAB3F3-7CFB-408A-9756-70F45BE325AC} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - DLL Proxy de Autochk.) -- C:\Windows\System32\acproxy.dll [12800] =>.Microsoft Corporation
O38 - TASK: {04E9E27D-20BA-4966-9A08-59E136EAC4E1} [64Bits][\Microsoft\Windows\SpacePort\SpaceAgentTask] - (.Microsoft Corporation - Configurações de Espaços de Armazenamento.) -- C:\WINDOWS\system32\SpaceAgent.exe [131584] =>.Microsoft Corporation
O38 - TASK: {0621FDBB-ADD5-44B7-A2AB-8288118B6295} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClient] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [102912] =>.Microsoft Corporation
O38 - TASK: {065C6248-D9B4-47F9-979E-EB6ECDE3CCC2} [64Bits][\Microsoft\Windows\Subscription\EnableLicenseAcquisition] - (.Microsoft Corporation - Acquire License From Store.) -- C:\WINDOWS\System32\ClipRenew.exe [136600] =>.Microsoft Corporation
O38 - TASK: {08ECD6F8-3E70-482C-9F54-C96A9C1A773F} [64Bits][\Microsoft\Windows\Management\Provisioning\Logon] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [73216] =>.Microsoft Corporation
O38 - TASK: {0F6456DB-4E19-4DC6-9D23-3C753B82FCEE} [64Bits][\Microsoft\Windows\Subscription\LicenseAcquisition] - (.Microsoft Corporation - Acquire License From Store.) -- C:\WINDOWS\System32\ClipRenew.exe [136600] =>.Microsoft Corporation
O38 - TASK: {158D3281-FEB3-47C2-87B9-EE652382C0AB} [64Bits][\Microsoft\Windows\Application Experience\StartupAppTask] - (.Microsoft Corporation - DLL da tarefa de exame de inicialização.) -- C:\Windows\System32\Startupscan.dll [17920] =>.Microsoft Corporation
O38 - TASK: {1674D42A-8575-4289-B53C-682FE1847EEC} [64Bits][\Microsoft\Office\Office 15 Subscription Heartbeat] - (.Microsoft Corporation - Office Subscription Licensing Heartbeat.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [316632] =>.Microsoft Corporation
O38 - TASK: {17A68EC1-555F-454C-9497-A48240207E9F} [64Bits][\Microsoft\Windows\Workplace Join\Recovery-Check] - (.Microsoft Corporation - Ferramenta de linha de comando DSREG.) -- C:\WINDOWS\System32\dsregcmd.exe [730624] =>.Microsoft Corporation
O38 - TASK: {2646432D-A31A-41EC-88D5-495FF767E1ED} [64Bits][\Microsoft\Windows\Time Zone\SynchronizeTimeZone] - (.Microsoft Corporation - TimeZone Sync Task.) -- C:\WINDOWS\system32\tzsync.exe [61440] =>.Microsoft Corporation
O38 - TASK: {26810429-E00E-44DC-8EB3-0F924A856085} [64Bits][\Microsoft\Windows\Shell\FamilySafetyMonitor] - (.Microsoft Corporation - Monitor de Proteção para a Família.) -- C:\WINDOWS\System32\wpcmon.exe [1430760] =>.Microsoft Corporation
O38 - TASK: {2C2F86B8-BDAB-4512-8288-0E346E601DB6} [64Bits][\ASC11_SkipUac_Pedro] - (.IObit - Advanced SystemCare 11.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [8241424] =>.IObit
O38 - TASK: {2C807F3D-B764-4990-BE1A-C2466CA7CF8E} [64Bits][\Microsoft\Windows\Clip\License Validation] - (.Microsoft Corporation - Client License Platform migration tool.) -- C:\WINDOWS\System32\ClipUp.exe [1263592] =>.Microsoft Corporation
O38 - TASK: {2D808D94-7193-4BE8-99E9-00C4118F789B} [64Bits][\TechSmith Updater] - (.TechSmith Corporation - TechSmith Updater.) -- C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [56704] =>.TechSmith Corporation
O38 - TASK: {32274688-6925-4C3C-AC5D-E7F3278E9F9E} [64Bits][\Microsoft\Windows\Speech\SpeechModelDownloadTask] - (.Microsoft Corporation - Speech Model Download Executable.) -- C:\Windows\System32\speech_onecore\common\SpeechModelDownload.exe [169984] =>.Microsoft Corporation
O38 - TASK: {36713542-0103-4035-B316-A447E72506AC} [64Bits][\Microsoft\Windows\PushToInstall\LoginCheck] - (.Microsoft Corporation - Ferramenta de Configuração do Gerenciador d.) -- C:\Windows\System32\sc.exe [69120] =>.Microsoft Corporation
O38 - TASK: {36EECAE1-3E34-4A61-8394-42D7F23F0455} [64Bits][\Microsoft\Windows\WwanSvc\NotificationTask] - (.Microsoft Corporation - Tarefa em Segundo Plano Sem Fio.) -- C:\WINDOWS\System32\WiFiTask.exe [461720] =>.Microsoft Corporation
O38 - TASK: {37292EA8-F458-47ED-A55C-5A3A1CCF5FD5} [64Bits][\Microsoft\Windows\WindowsUpdate\sih] - (.Microsoft Corporation - Cliente SIH.) -- C:\WINDOWS\System32\sihclient.exe [266752] =>.Microsoft Corporation
O38 - TASK: {37449A31-039E-4B1D-8F13-E8C24D7833D4} [64Bits][\Microsoft\Windows\WindowsUpdate\sihboot] - (.Microsoft Corporation - Cliente SIH.) -- C:\WINDOWS\System32\sihclient.exe [266752] =>.Microsoft Corporation
O38 - TASK: {37E715E6-383C-4ADF-813E-10FF9F50D9F7} [64Bits][\Microsoft\Windows\Chkdsk\SyspartRepair] - (.Microsoft Corporation - Utilitário bcdboot.) -- C:\WINDOWS\system32\bcdboot.exe [209920] =>.Microsoft Corporation
O38 - TASK: {421A0C7D-3785-4403-A75D-316168E34206} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Maintenance Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [39424] =>.Microsoft Corporation
O38 - TASK: {483FAC9D-5977-47EF-80D1-80E063A3AAAB} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\WINDOWS\system32\appidpolicyconverter.exe [158720] =>.Microsoft Corporation
O38 - TASK: {4CC7ABBD-2754-475A-B3A8-31D51CB4EAD0} [64Bits][\GoogleUpdateTaskUserS-1-5-21-3971250647-479220780-3394640940-1002UA] - (.Google Inc. - Google Installer.) -- C:\Users\Pedro\AppData\Local\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {4FC5FA4E-102D-41FF-AD93-38654F2D12F2} [64Bits][\microsoft\windows\applicationdata\appuriverifierinstall] - (.Microsoft Corporation - Verificador de Registro de Manipuladores de.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [109056] =>.Microsoft Corporation
O38 - TASK: {51372E51-C6B7-4710-ACEB-69D67B762E1F} [64Bits][\Microsoft\Windows\rempl\shell-usoscan] - (.Microsoft Corporation - remsh.) -- C:\Program Files\rempl\remsh.exe [1172984] =>.Microsoft Corporation
O38 - TASK: {5267392F-5BB8-45A6-AD93-10211E2F8850} [64Bits][\Microsoft\Windows\SpacePort\SpaceManagerTask] - (.Microsoft Corporation - Storage Spaces Manager.) -- C:\WINDOWS\system32\spaceman.exe [35328] =>.Microsoft Corporation
O38 - TASK: {568AC0B6-44BB-4D3E-B7CB-D4649085FAB7} [64Bits][\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization] - (.Microsoft Corp. - Desfragmentador de disco do Windows.) -- C:\WINDOWS\system32\defrag.exe [185856] =>.Microsoft Corp.
O38 - TASK: {56FBE318-1AAE-4BEA-8362-21632D78942F} [64Bits][\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [399872] =>.Microsoft Corporation
O38 - TASK: {5A201377-91EE-4904-B2C6-9F7D7456A03F} [64Bits][\Microsoft\Windows\Device Information\Device] - (.Microsoft Corporation - Device Census.) -- C:\WINDOWS\system32\devicecensus.exe [35224] =>.Microsoft Corporation
O38 - TASK: {5C020530-D866-421B-B15E-7EB9C7FA4D3B} [64Bits][\Microsoft\Windows\DiskCleanup\SilentCleanup] - (.Microsoft Corporation - Gerenciador de Limpeza de Espaço em Disco p.) -- C:\Windows\System32\cleanmgr.exe [219648] =>.Microsoft Corporation
O38 - TASK: {5CDC9F2F-69BB-48B9-A707-2D303BE314F5} [64Bits][\ASC11_PerformanceMonitor] - (.IObit - Performance Monitor.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [3471648] =>.IObit
O38 - TASK: {5F5BF124-A1B2-4BEB-8C6B-5AD2F2D1C3DB} [64Bits][\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser] - (.Microsoft Corporation - Tarefa de Analisador de Experiência de Cont.) -- C:\WINDOWS\System32\MbaeParserTask.exe [114176] =>.Microsoft Corporation
O38 - TASK: {61BAF05A-8050-481F-9368-9B62A53BC9C5} [64Bits][\microsoft\windows\applicationdata\appuriverifierdaily] - (.Microsoft Corporation - Verificador de Registro de Manipuladores de.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [109056] =>.Microsoft Corporation
O38 - TASK: {650751B8-0586-401C-95FF-65523D62D989} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Schedule Scan] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [39424] =>.Microsoft Corporation
O38 - TASK: {67889EEC-D7B4-43D3-B82C-D0DBA3522591} [64Bits][\Microsoft\Windows\WCM\WiFiTask] - (.Microsoft Corporation - Tarefa em Segundo Plano Sem Fio.) -- C:\WINDOWS\System32\WiFiTask.exe [461720] =>.Microsoft Corporation
O38 - TASK: {6831246E-D3E2-469C-9079-23FA53AC7712} [64Bits][\Microsoft\Windows\Printing\EduPrintProv] - (.Microsoft Corporation - Printer Provision Utility for EDU.) -- C:\WINDOWS\system32\eduprintprov.exe [95232] =>.Microsoft Corporation
O38 - TASK: {6AF2B5AF-12F7-4A18-8717-7EE7080D2E29} [64Bits][\Microsoft\Windows\ApplicationData\CleanupTemporaryState] - (.Microsoft Corporation - Windows Application Data API Server.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [367336] =>.Microsoft Corporation
O38 - TASK: {6F0BC9E8-7975-4BBA-BA11-1B177AA4EBB4} [64Bits][\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers] - (.Microsoft Corporation - Módulo de Instalação de Driver.) -- C:\WINDOWS\System32\drvinst.exe [160256] =>.Microsoft Corporation
O38 - TASK: {704D5956-0326-45EC-B2F4-43622919C662} [64Bits][\Adobe Flash Player PPAPI Notifier] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_pepper.exe [1362432] =>.Adobe Systems Incorporated
O38 - TASK: {70F1D577-5C2C-488A-A90C-2282E826A8C0} [64Bits][\Microsoft\Windows\Windows Media Sharing\UpdateLibrary] - (.Microsoft Corporation - Aplicativo de Configuração do Serviço de co.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe [69120] =>.Microsoft Corporation
O38 - TASK: {724A82BA-0CD9-4932-A8F8-AE155346DC7A} [64Bits][\Microsoft\Windows\Workplace Join\Automatic-Device-Join] - (.Microsoft Corporation - Ferramenta de linha de comando DSREG.) -- C:\WINDOWS\System32\dsregcmd.exe [730624] =>.Microsoft Corporation
O38 - TASK: {7940F693-99A6-4EAC-ADF7-8DDB0F9B109A} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {7BA3B21F-8580-469B-AAA5-055CC6BE7644} [64Bits][\GoogleUpdateTaskUserS-1-5-21-3971250647-479220780-3394640940-1002Core] - (.Google Inc. - Google Installer.) -- C:\Users\Pedro\AppData\Local\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {823907E4-225B-4EF7-AF4B-8BD3F3493491} [64Bits][\Microsoft\Windows\Bluetooth\UninstallDeviceTask] - (.Microsoft Corporation - Tarefa de Dispositivo de Desinstalação de B.) -- C:\Windows\System32\BthUdTask.exe [40448] =>.Microsoft Corporation
O38 - TASK: {82B5AAEF-39CD-42E6-839C-D4724378C033} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - Ferramenta de Configuração do Gerenciador d.) -- C:\Windows\System32\sc.exe [69120] =>.Microsoft Corporation
O38 - TASK: {8BA021CB-2C63-4577-BA9B-DADCEBAC7A80} [64Bits][\Remove compartilhamento] - (.PEDRO\Pedro - Remove compartilhamento.) -- C:\Users\Pedro\Documents\remove compartilhamento.bat [131]
O38 - TASK: {8D10638E-48BA-4258-B09C-ACB4343F3E8E} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [399872] =>.Microsoft Corporation
O38 - TASK: {8DC4F6F2-5AC8-41B5-8461-383B58804B47} [64Bits][\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask] - (.Microsoft Corporation - MDMAgent.) -- C:\WINDOWS\system32\MDMAgent.exe [108544] =>.Microsoft Corporation
O38 - TASK: {918820CD-A709-4BBE-9360-276DEB1D4189} [64Bits][\Microsoft\Office\Office ClickToRun Service Monitor] - (.Microsoft Corporation - Microsoft Office Click-to-Run Client.) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [978672] =>.Microsoft Corporation
O38 - TASK: {9202D2AF-F1E6-4D6B-AA7E-FC0654E3635A} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Mecanismo de Filtragem Básica.) -- C:\Windows\System32\bfe.dll [841216] =>.Microsoft Corporation
O38 - TASK: {95812E91-F632-41D2-BA27-1B515BFBF299} [64Bits][\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask] - (.Microsoft Corporation - Servidor COM de Assistência Remota do Windo.) -- C:\Windows\System32\raserver.exe [128000] =>.Microsoft Corporation
O38 - TASK: {9C7D670F-D8AA-4310-B11E-79D3738AB035} [64Bits][\Microsoft\Windows\DiskFootprint\Diagnostics] - (.Microsoft Corporation - DiskSnapshot.exe.) -- C:\WINDOWS\system32\disksnapshot.exe [87040] =>.Microsoft Corporation
O38 - TASK: {A7C57A41-D764-4AAB-BBDE-BB8DAA2BE5DD} [64Bits][\Microsoft\Windows\UNP\RunUpdateNotificationMgr] - (.Microsoft Corporation - Update Notification Pipeline Manager.) -- C:\WINDOWS\System32\UNP\UpdateNotificationMgr.exe [378264] =>.Microsoft Corporation
O38 - TASK: {A8E38795-E6D5-44C1-83B8-D3D0811ACE2E} [64Bits][\Microsoft\Windows\ApplicationData\DsSvcCleanup] - (.Microsoft Corporation - Data Sharing Service Maintenance Driver.) -- C:\WINDOWS\system32\dstokenclean.exe [12800] =>.Microsoft Corporation
O38 - TASK: {AE29E8A6-9708-4CB5-8282-D7F7291DCC34} [64Bits][\Microsoft\Windows\Location\WindowsActionDialog] - (.Microsoft Corporation - Agente de Diálogo de Ação do Windows.) -- C:\WINDOWS\System32\WindowsActionDialog.exe [59392] =>.Microsoft Corporation
O38 - TASK: {B2B85895-09A2-4BC3-BBF9-9B74780BFE62} [64Bits][\Microsoft\Windows\SharedPC\Account Cleanup] - (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [194560] =>.Microsoft Corporation
O38 - TASK: {B38EADAA-FBBE-4A90-BAE4-3F6BCC5C5BC7} [64Bits][\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [138144] =>.Microsoft Corporation
O38 - TASK: {B526DD0E-F682-49E6-AEA6-C62E139F481E} [64Bits][\Microsoft\Office\Office Automatic Updates] - (.Microsoft Corporation - Microsoft Office Click-to-Run Client.) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [978672] =>.Microsoft Corporation
O38 - TASK: {B56FBD02-3851-456D-B119-FEAC53DD79EE} [64Bits][\StartIsBack health check] - (.www.startisback.com - StartIsBack Helper Tool.) -- C:\Program Files (x86)\StartIsBack\startscreen.exe [55840] =>.www.startisback.com
O38 - TASK: {BB977AB5-18D9-424E-9C60-494AAF177276} [64Bits][\Adobe Flash Player NPAPI Notifier] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe [1362432] =>.Adobe Systems Incorporated
O38 - TASK: {BC40FCF6-98AA-466D-98D4-D4D532C3007D} [64Bits][\Microsoft\Windows\NlaSvc\WiFiTask] - (.Microsoft Corporation - Tarefa em Segundo Plano Sem Fio.) -- C:\WINDOWS\System32\WiFiTask.exe [461720] =>.Microsoft Corporation
O38 - TASK: {BEF53ECE-EA8A-4B90-87DD-07DB4DFCB3D0} [64Bits][\Microsoft\Windows\Management\Provisioning\Cellular] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [73216] =>.Microsoft Corporation
O38 - TASK: {C05CF805-420D-41C7-9E13-86ED6E546B7E} [64Bits][\Microsoft\Windows\Sysmain\WsSwapAssessmentTask] - (.Microsoft Corporation - Host de Serviço Superfetch.) -- C:\Windows\System32\sysmain.dll [970240] =>.Microsoft Corporation
O38 - TASK: {C0CA1747-6000-409E-976F-9150EB7FBDF7} [64Bits][\Microsoft\Windows\WaaSMedic\PerformRemediation] - (.Microsoft Corporation - WaasMedic.) -- C:\WINDOWS\System32\WaaSMedic.exe [348160] =>.Microsoft Corporation
O38 - TASK: {C8252966-561E-44F5-8E10-113984BF4843} [64Bits][\Microsoft\Windows\Time Synchronization\SynchronizeTime] - (.Microsoft Corporation - Ferramenta de Configuração do Gerenciador d.) -- C:\Windows\System32\sc.exe [69120] =>.Microsoft Corporation
O38 - TASK: {C89FB80E-7881-4C3F-9506-00342D8BC3F1} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - Limpeza do pacote do Idioma MUI.) -- C:\WINDOWS\system32\lpremove.exe [58368] =>.Microsoft Corporation
O38 - TASK: {CD1140B4-32E4-4657-AB7D-3E09C8AD4B96} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver] - (.Microsoft Corporation - Resolvedor do Usuário de Diagnóstico de Dis.) -- C:\WINDOWS\system32\DFDWiz.exe [51712] =>.Microsoft Corporation
O38 - TASK: {CF842F82-5CE4-44CE-93D4-750EE07191DC} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Desfragmentador de disco do Windows.) -- C:\WINDOWS\system32\defrag.exe [185856] =>.Microsoft Corp.
O38 - TASK: {D0218C70-9C99-4043-BF17-667E1AE5C42E} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Reboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [399872] =>.Microsoft Corporation
O38 - TASK: {D0A89826-6023-4661-975D-0CE62FBF194D} [64Bits][\Microsoft\Windows\Location\Notifications] - (.Microsoft Corporation - Notificação do Local.) -- C:\WINDOWS\System32\LocationNotificationWindows.exe [67584] =>.Microsoft Corporation
O38 - TASK: {D2E38DD0-019E-42DB-B34D-2CE5DC12ED7A} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\WINDOWS\system32\appidcertstorecheck.exe [18944] =>.Microsoft Corporation
O38 - TASK: {D711A0E2-F78C-4616-B936-04ADE2E761BB} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {D80AA3A2-189B-4A11-8828-511E6BAE5426} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- C:\Windows\System32\wermgr.exe [194456] =>.Microsoft Corporation
O38 - TASK: {DBC0E7D7-373A-4F38-A231-44664D6CEEF7} [64Bits][\AutoPico Daily Restart] - (.@ByELDI - AutoPico.) -- C:\Program Files\KMSpico\AutoPico.exe [743616] =>HackTool.KMSpico
O38 - TASK: {DD58B741-9950-4D0C-BB33-06D20EC7EB67} [64Bits][\Adobe Flash Player Updater] - (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 29.0 r0.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [272384] =>.Adobe Systems Incorporated
O38 - TASK: {DE51FC11-6C38-440A-A9D2-2A0602690914} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [138144] =>.Microsoft Corporation
O38 - TASK: {E0D45B22-1A56-43FE-854C-DAFD1DDA1D61} [64Bits][\Microsoft\Windows\DUSM\dusmtask] - (.Microsoft Corporation - DUSM Task.) -- C:\WINDOWS\System32\dusmtask.exe [34816] =>.Microsoft Corporation
O38 - TASK: {E3DBE120-A4C2-4CD4-A364-C51992B36C98} [64Bits][\Microsoft\Windows\SystemRestore\SR] - (.Microsoft Corporation - Tarefas de tela de fundo da Proteção de Sis.) -- C:\WINDOWS\system32\srtasks.exe [56832] =>.Microsoft Corporation
O38 - TASK: {E5182B77-08AA-49E5-AE8E-806A8F509499} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start] - (.Microsoft Corporation - Ferramenta de Configuração do Gerenciador d.) -- C:\Windows\System32\sc.exe [69120] =>.Microsoft Corporation
O38 - TASK: {E52928DD-BCA2-4E32-9B84-FFA7606694BE} [64Bits][\Microsoft\XblGameSave\XblGameSaveTask] - (.Microsoft Corporation - XblGameSave Standby Task.) -- C:\WINDOWS\System32\XblGameSaveTask.exe [31744] =>.Microsoft Corporation
O38 - TASK: {EAE44DBA-F158-4EAA-8864-BCB05E36C20E} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Windows SQM Consolidator.) -- C:\WINDOWS\System32\wsqmcons.exe [91136] =>.Microsoft Corporation
O38 - TASK: {F0A590C9-9AA0-48BB-B8D4-77D99A67BB0B} [64Bits][\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup] - (.Microsoft Corporation - DLL do Cliente de Implantação AppX.) -- C:\Windows\System32\AppxDeploymentClient.dll [688064] =>.Microsoft Corporation
O38 - TASK: {F6027CB3-9A58-415A-80F2-B1404204D4F5} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [102912] =>.Microsoft Corporation
O38 - TASK: {F8A23064-31D9-4870-9A94-327935B22073} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector] - (.Microsoft Corporation - Módulo Diagnóstico de Falhas de Discos do W.) -- C:\Windows\System32\dfdts.dll [45056] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\PushToInstall\Registration - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [pushtoinstall registration] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Autochk\Proxy - (.Microsoft Corporation.) -- C:\Windows\System32\acproxy.dll [acproxy.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - (.Microsoft Corporation.) -- C:\WINDOWS\system32\SpaceAgent.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient - (.Microsoft Corporation.) -- C:\WINDOWS\system32\dmclient.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition - (.Microsoft Corporation.) -- C:\WINDOWS\System32\ClipRenew.exe [-e] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Management\Provisioning\Logon - (.Microsoft Corporation.) -- C:\WINDOWS\system32\ProvTool.exe [/turn 5] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Subscription\LicenseAcquisition - (.Microsoft Corporation.) -- C:\WINDOWS\System32\ClipRenew.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask - (.Microsoft Corporation.) -- C:\Windows\System32\Startupscan.dll [Startupscan.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat - (.Microsoft Corporation.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Workplace Join\Recovery-Check - (.Microsoft Corporation.) -- C:\WINDOWS\System32\dsregcmd.exe [/checkrecovery] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - (.Microsoft Corporation.) -- C:\WINDOWS\system32\tzsync.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - (.Microsoft Corporation.) -- C:\WINDOWS\System32\wpcmon.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\ASC11_SkipUac_Pedro - (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [/SkipUac] =>.IObit
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Clip\License Validation - (.Microsoft Corporation.) -- C:\WINDOWS\System32\ClipUp.exe [-p -s -o] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\TechSmith Updater - (.TechSmith Corporation.) -- C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [all] =>.TechSmith Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - (.Microsoft Corporation.) -- C:\Windows\System32\speech_onecore\common\SpeechModelDownload.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\PushToInstall\LoginCheck - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [pushtoinstall login] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\WwanSvc\NotificationTask - (.Microsoft Corporation.) -- C:\WINDOWS\System32\WiFiTask.exe [wwan] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\WindowsUpdate\sih - (.Microsoft Corporation.) -- C:\WINDOWS\System32\sihclient.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot - (.Microsoft Corporation.) -- C:\WINDOWS\System32\sihclient.exe [/boot] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Chkdsk\SyspartRepair - (.Microsoft Corporation.) -- C:\WINDOWS\system32\bcdboot.exe [C:\Windows] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - (.Microsoft Corporation.) -- C:\WINDOWS\System32\usoclient.exe [StartInstall] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\AppID\PolicyConverter - (.Microsoft Corporation.) -- C:\WINDOWS\system32\appidpolicyconverter.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3971250647-479220780-3394640940-1002UA - (.Google Inc..) -- C:\Users\Pedro\AppData\Local\Google\Update\GoogleUpdate.exe [/ua] =>.Google Inc.
C:\WINDOWS\System32\Tasks\microsoft\windows\applicationdata\appuriverifierinstall - (.Microsoft Corporation.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\rempl\shell-usoscan - (.Microsoft Corporation.) -- C:\Program Files\rempl\remsh.exe [/RunUsoScanOnly] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - (.Microsoft Corporation.) -- C:\WINDOWS\system32\spaceman.exe [/Work] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - (.Microsoft Corp..) -- C:\WINDOWS\system32\defrag.exe [-c -h -g -# -m 8 -i 13500] =>.Microsoft Corp.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval - (.Microsoft Corporation.) -- C:\WINDOWS\System32\MusNotification.exe [Display] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Device Information\Device - (.Microsoft Corporation.) -- C:\WINDOWS\system32\devicecensus.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - (.Microsoft Corporation.) -- C:\Windows\System32\cleanmgr.exe [/autoclean] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\ASC11_PerformanceMonitor - (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [/Task] =>.IObit
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - (.Microsoft Corporation.) -- C:\WINDOWS\System32\MbaeParserTask.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\microsoft\windows\applicationdata\appuriverifierdaily - (.Microsoft Corporation.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - (.Microsoft Corporation.) -- C:\WINDOWS\System32\usoclient.exe [StartScan] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\WCM\WiFiTask - (.Microsoft Corporation.) -- C:\WINDOWS\System32\WiFiTask.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Printing\EduPrintProv - (.Microsoft Corporation.) -- C:\WINDOWS\system32\eduprintprov.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - (.Microsoft Corporation.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [Windows.Storage.ApplicationData.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - (.Microsoft Corporation.) -- C:\WINDOWS\System32\drvinst.exe [6] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_pepper.exe [-check pepperplugin] =>.Adobe Systems Incorporated
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - (.Microsoft Corporation.) -- C:\WINDOWS\System32\dsregcmd.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/ua] =>.Google Inc.
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3971250647-479220780-3394640940-1002Core - (.Google Inc..) -- C:\Users\Pedro\AppData\Local\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - (.Microsoft Corporation.) -- C:\Windows\System32\BthUdTask.exe [$(Arg0)] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [config upnphost start= auto] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Remove compartilhamento - (.PEDRO\Pedro.) -- C:\Users\Pedro\Documents\remove compartilhamento.bat []
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display - (.Microsoft Corporation.) -- C:\WINDOWS\System32\MusNotification.exe [Display] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - (.Microsoft Corporation.) -- C:\WINDOWS\system32\MDMAgent.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor - (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [/WatchService] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - (.Microsoft Corporation.) -- C:\Windows\System32\bfe.dll [bfe.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - (.Microsoft Corporation.) -- C:\Windows\System32\raserver.exe [/offerraupdate] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics - (.Microsoft Corporation.) -- C:\WINDOWS\system32\disksnapshot.exe [-z] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr - (.Microsoft Corporation.) -- C:\WINDOWS\System32\UNP\UpdateNotificationMgr.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - (.Microsoft Corporation.) -- C:\WINDOWS\system32\dstokenclean.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog - (.Microsoft Corporation.) -- C:\WINDOWS\System32\WindowsActionDialog.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SharedPC\Account Cleanup - (.Microsoft Corporation.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - (.Microsoft Corporation.) -- C:\WINDOWS\system32\compattelrunner.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Office\Office Automatic Updates - (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [/update SCHEDULEDTASK displaylevel=False] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\StartIsBack health check - (.www.startisback.com.) -- C:\Program Files (x86)\StartIsBack\startscreen.exe [/check] =>.www.startisback.com
C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe [-check plugin] =>.Adobe Systems Incorporated
C:\WINDOWS\System32\Tasks\Microsoft\Windows\NlaSvc\WiFiTask - (.Microsoft Corporation.) -- C:\WINDOWS\System32\WiFiTask.exe [nla] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Management\Provisioning\Cellular - (.Microsoft Corporation.) -- C:\WINDOWS\system32\ProvTool.exe [/turn 7] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - (.Microsoft Corporation.) -- C:\Windows\System32\sysmain.dll [sysmain.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\WaaSMedic\PerformRemediation - (.Microsoft Corporation.) -- C:\WINDOWS\System32\WaaSMedic.exe [None] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [w32time task_ed] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\MUI\LPRemove - (.Microsoft Corporation.) -- C:\WINDOWS\system32\lpremove.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - (.Microsoft Corporation.) -- C:\WINDOWS\system32\DFDWiz.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Defrag\ScheduledDefrag - (.Microsoft Corp..) -- C:\WINDOWS\system32\defrag.exe [-c -h -o -$] =>.Microsoft Corp.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - (.Microsoft Corporation.) -- C:\WINDOWS\System32\MusNotification.exe [RebootDialog] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications - (.Microsoft Corporation.) -- C:\WINDOWS\System32\LocationNotificationWindows.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - (.Microsoft Corporation.) -- C:\WINDOWS\system32\appidcertstorecheck.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - (.Microsoft Corporation.) -- C:\Windows\System32\wermgr.exe [-upload] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart - (.@ByELDI.) -- C:\Program Files\KMSpico\AutoPico.exe [/silent]
C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [] =>.Adobe Systems Incorporated
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - (.Microsoft Corporation.) -- C:\WINDOWS\system32\compattelrunner.exe [-maintenance] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\DUSM\dusmtask - (.Microsoft Corporation.) -- C:\WINDOWS\System32\dusmtask.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SystemRestore\SR - (.Microsoft Corporation.) -- C:\WINDOWS\system32\srtasks.exe [ExecuteScheduledSPPCreation] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [wuauserv] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\XblGameSave\XblGameSaveTask - (.Microsoft Corporation.) -- C:\WINDOWS\System32\XblGameSaveTask.exe [standby] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - (.Microsoft Corporation.) -- C:\WINDOWS\System32\wsqmcons.exe [] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - (.Microsoft Corporation.) -- C:\Windows\System32\AppxDeploymentClient.dll [C:\Windows\System32\AppxDeploymentClient.dll] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - (.Microsoft Corporation.) -- C:\WINDOWS\system32\dmclient.exe [utcwnf] =>.Microsoft Corporation
C:\WINDOWS\System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - (.Microsoft Corporation.) -- C:\Windows\System32\dfdts.dll [dfdts.dll] =>.Microsoft Corporation

---\ Aplicações iniciadas por registo & pastas (23) - 4s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
O4 - HKLM\..\Run: [Certificate Synchronizer] . (.Oberthur Technologies - OT Certificate Synchronizer Application.) -- C:\Program Files\Oberthur Technologies\AWP\OTCertSynchronizer.exe {2DD0195E4C2A2BB2DD729803591178E7}
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe =>.Intel Corporation
O4 - HKLM\..\Run: [tvncontrol] . (.GlavSoft LLC. - TightVNC Server.) -- C:\Program Files\TightVNC\tvnserver.exe =>.GlavSoft LLC.®
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe =>.IDT, Inc.
O4 - HKLM\..\Run: [egui] . (.ESET - ESET command line interface.) -- C:\Program Files\ESET\ESET Security\ecmds.exe =>.ESET, spol. s r.o.®
O4 - HKCU\..\Run: [Advanced SystemCare 11] . (.IObit - Advanced SystemCare Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe =>.IObit Information Technology®
O4 - HKCU\..\Run: [SmartRAM] . (.IObit - Monitor and release memory.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Suo10_SmartRAM.exe =>.IObit Information Technology®
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Google Update Core.) -- C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe =>.Google Inc®
O4 - HKCU\..\Run: [GoogleDriveSync] . (...) -- C:\Program Files\Google\Drive\googledrivesync.exe =>.Google Inc®
O4 - HKCU\..\Run: [Cobian Backup 11] . (.Luis Cobian, CobianSoft - Cobian Backup 11 Gravity.) -- C:\Program Files (x86)\Cobian Backup 11\Cobian.exe =>.Luis Cobian, CobianSoft
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_10B0E023327055204CEEBBDFD62EA309] . (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - HKLM\..\Wow6432Node\Run: [DFX] . (...) -- C:\Program Files (x86)\DFX\DFX.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems, Incorporated®
O4 - HKLM\..\Wow6432Node\Run: [KeePass 2 PreLoad] . (.Dominik Reichl - KeePass.) -- C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-21-3971250647-479220780-3394640940-1002\..\Run: [Advanced SystemCare 11] . (.IObit - Advanced SystemCare Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe =>.IObit Information Technology®
O4 - HKUS\S-1-5-21-3971250647-479220780-3394640940-1002\..\Run: [SmartRAM] . (.IObit - Monitor and release memory.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Suo10_SmartRAM.exe =>.IObit Information Technology®
O4 - HKUS\S-1-5-21-3971250647-479220780-3394640940-1002\..\Run: [Google Update] . (.Google Inc. - Google Update Core.) -- C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe =>.Google Inc®
O4 - HKUS\S-1-5-21-3971250647-479220780-3394640940-1002\..\Run: [GoogleDriveSync] . (...) -- C:\Program Files\Google\Drive\googledrivesync.exe =>.Google Inc®
O4 - HKUS\S-1-5-21-3971250647-479220780-3394640940-1002\..\Run: [Cobian Backup 11] . (.Luis Cobian, CobianSoft - Cobian Backup 11 Gravity.) -- C:\Program Files (x86)\Cobian Backup 11\Cobian.exe =>.Luis Cobian, CobianSoft
O4 - HKUS\S-1-5-21-3971250647-479220780-3394640940-1002\..\Run: [GoogleChromeAutoLaunch_10B0E023327055204CEEBBDFD62EA309] . (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®

---\ Processos lançados (53) - 9s
[MD5.1D4F08B2531E169864B3AFFF52BE4574] - (.Code Sector - TeraCopy Service.) -- C:\Program Files\TeraCopy\TeraCopyService.exe [110416] [PID.1640] =>.Code Sector®
[MD5.437B423586BC2DB5957EDB2B672CB7F1] - (.@ByELDI - Service_KMS.) -- C:\Program Files\KMSpico\Service_KMS.exe [743616] [PID.3456] =>HackTool.KMSpico
[MD5.A3A836DDAC13A685E0E88FD260EEBBAA] - (.eFolder - Sync Service.) -- C:\Program Files (x86)\vBox\bin\agent_service.exe [11729496] [PID.3512] {0664CADB13C394F908C7E2BDF7114CC6}
[MD5.56C10D3338B01D3FBCC5AF24B3833E1C] - (.GlavSoft LLC. - TightVNC Server.) -- C:\Program Files\TightVNC\tvnserver.exe [2179056] [PID.3640] =>.GlavSoft LLC.®
[MD5.CF11606953160F12EFB95351E4A20AA3] - (.TeamViewer GmbH - TeamViewer 13.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11294448] [PID.3656] =>.TeamViewer GmbH®
[MD5.439BD966130226F464DC15F55ABD266E] - (.TechSmith Corporation - TechSmith Uploader Service.) -- C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384] [PID.3680] =>.TechSmith Corporation
[MD5.900236357482B00944826354EEC6B93F] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe [288848] [PID.1788] =>.Google Inc®
[MD5.F107219B133E7E574DA052C5C88FFBF3] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe [366672] [PID.2184] =>.Google Inc®
[MD5.5BCF5E89DD0CCC45119A3062D332E334] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [1056016] [PID.2780] =>.IObit Information Technology®
[MD5.4677802CA243E50455955B7B29D4300D] - (.IObit - Performance Monitor.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [3471648] [PID.9704] =>.IObit Information Technology®
[MD5.56C10D3338B01D3FBCC5AF24B3833E1C] - (.GlavSoft LLC. - TightVNC Server.) -- C:\Program Files\TightVNC\tvnserver.exe [2179056] [PID.8632] =>.GlavSoft LLC.®
[MD5.4FFB44AA0468738E30BE0DD70618A631] - (.IObit - Advanced SystemCare Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3580176] [PID.8876] =>.IObit Information Technology®
[MD5.365012E25FA02F7B2A8851E6CE911142] - (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Security\egui.exe [6962808] [PID.10816] =>.ESET, spol. s r.o.®
[MD5.145483DD8BFA326672B07D22217ADF7E] - (.IObit - Monitor and release memory.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Suo10_SmartRAM.exe [560400] [PID.8016] =>.IObit Information Technology®
[MD5.FE1ABBE2E99FE69C48BC4AC1F710941A] - (...) -- C:\Program Files\Google\Drive\googledrivesync.exe [46139776] [PID.1060] =>.Google Inc®
[MD5.E3D991C8B9F7756538DE5C0A26647F65] - (.TechSmith Corporation - Snagit.) -- C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe [7432512] [PID.13256] =>.TechSmith Corporation®
[MD5.8B238DD470FF08B4A95E1C3A10085D17] - (.eFolder - Sync Tool.) -- C:\Program Files (x86)\vBox\bin\agent_gui.exe [8704088] [PID.4236] {0664CADB13C394F908C7E2BDF7114CC6}
[MD5.7DCAAFA1C998B79147126ED95A419C9D] - (...) -- C:\Program Files (x86)\DFX\DFX.exe [1272792] [PID.4052]
[MD5.900236357482B00944826354EEC6B93F] - (.Google Inc. - Google Crash Handler.) -- C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleCrashHandler.exe [288848] [PID.10176] =>.Google Inc®
[MD5.F107219B133E7E574DA052C5C88FFBF3] - (.Google Inc. - Google Crash Handler.) -- C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleCrashHandler64.exe [366672] [PID.6688] =>.Google Inc®
[MD5.11C79E0D1A1B332B79D1A1402052A4D0] - (.TechSmith Corporation - Snagit RPC Helper.) -- C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe [151872] [PID.12664] =>.TechSmith Corporation®
[MD5.3B954E19B9DE22782EA9213A1C2600FE] - (. - DFX.) -- C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe [130520] [PID.8392] =>.Power Technology®
[MD5.9F92359D96AA5544C58610BC253FE5ED] - (. - DFX.) -- C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe [131544] [PID.4764] =>.Power Technology®
[MD5.0A1810F3CF866F67856C8A4E98194493] - (.TechSmith Corporation - TechSmith HTML Help Helper.) -- C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe [46080] [PID.392] =>.TechSmith Corporation
[MD5.FE1ABBE2E99FE69C48BC4AC1F710941A] - (...) -- C:\Program Files\Google\Drive\googledrivesync.exe [46139776] [PID.11436] =>.Google Inc®
[MD5.27954CE3A3AFDBC91C91303AF50FADF7] - (.TechSmith Corporation - Snagit Editor.) -- C:\Program Files (x86)\TechSmith\Snagit 12\snagiteditor.exe [8587072] [PID.11560] =>.TechSmith Corporation®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.8260] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.2760] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.11284] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.8400] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.10424] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.7576] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.7392] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.12856] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.9240] =>.Google Inc®
[MD5.CED6284C4A1420362612D64FF5845ADB] - (.IObit - Advanced SystemCare 11.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [8241424] [PID.12588] =>.IObit Information Technology®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.4304] =>.Google Inc®
[MD5.973CCF5B14ACF32E7A8B9CD3CE8ED23C] - (...) -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe [478720] [PID.11864] =>.Microsoft Corporation
[MD5.EADA81DD4F0AF896FE9D4F0D1EB51861] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x64__kzf8qxf38zg5c\SkypeHost.exe [86528] [PID.7076] =>.Skype Technologies
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.2624] =>.Google Inc®
[MD5.6189C8A4DD0C54A28429CAF3F101908C] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3886672] [PID.12876] =>.Tonec Inc.
[MD5.BD95E822E7A958BBCA842D078426A151] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe [269848] [PID.10188] =>.Tonec Inc.®
[MD5.58BF7714A312698108A96D0DE2BB6825] - (.CobianSoft, Luis Cobian - Cobian Backup Gravity VSC Requester.) -- C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [67584] [PID.11512] =>.CobianSoft, Luis Cobian
[MD5.4EB0E1DE875819141C23491B1BC39D74] - (.Luis Cobian, CobianSoft - Cobian Backup 11 Gravity.) -- C:\Program Files (x86)\Cobian Backup 11\Cobian.exe [720896] [PID.11656] =>.Luis Cobian, CobianSoft
[MD5.6BDB90D0D8235A746F3C0F554B6F7181] - (.Luis Cobian, CobianSoft - Cobian backup 11 Gravity - Interface.) -- C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe [4407808] [PID.12784] =>.Luis Cobian, CobianSoft
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.4976] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.10560] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.12276] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.8976] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.11444] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.11740] =>.Google Inc®
[MD5.23201D6BE8A39AB70B3C263F2B9F4F80] - (.Google Inc. - Google Chrome.) -- C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe [1590616] [PID.9400] =>.Google Inc®
[MD5.CE85C77661695DB04605CDE5444ADB7E] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Pedro\Desktop\ZHPDiag3.exe [3043712] [PID.1808] =>.Nicolas Coolman

---\ Google Chrome, Arranque,Pesquisa,Extensões (29) - 1s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://banananalytics.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com.br =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://browsec.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://drah7iczdw1tu.cloudfront.net =>.SUP.CloudfrontNet
G0 - GCSP: Preferences [User Data\Default][HomePage] http://publicsuffix.org
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.google-analytics.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://stats.g.doubleclick.net
G0 - GCSP: Preferences [User Data\Default][HomePage] http://tracking.pushcrew.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google-analytics.com =>.Google Inc.
G2 - GCE: Preference [Pedro][User Data\Default][fhplmmllnpjjlncfjpbbpjadoeijkogc]
G2 - GCE: Preference [Pedro][User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [Pedro][User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [Pedro][User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [Pedro][User Data\Default] [bbmegnmpleoagolcnjnejdacakedpcgd] IObit Surfing Protection & Ads Removal =>.IObit
G2 - GCE: Preference [Pedro][User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [Pedro][User Data\Default] [cgjnhhjpfcdhbhlcmmjppicjmgfkppok] DownAlbum =>.inDream
G2 - GCE: Preference [Pedro][User Data\Default] [chgpmaaockmdehmidghebcjafhihlgha] Hola Video Accelerator
G2 - GCE: Preference [Pedro][User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [Pedro][User Data\Default] [fipcbkgepjlnemlkgialpomkajcpneop]
G2 - GCE: Preference [Pedro][User Data\Default] [fllaojicojecljbmefodhfapmkghcbnh] =>.ga-extension-publishers {Désactivation Google Analytics}
G2 - GCE: Preference [Pedro][User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [Pedro][User Data\Default] [jjmpnmcdcpmklbklngnnbhmalafjdkhk] Bradesco
G2 - GCE: Preference [Pedro][User Data\Default] [lmjegmlicamnimmfhcmpkclmigmmcbeh] Application Launcher for Drive (by Google) =>.Google Inc.
G2 - GCE: Preference [Pedro][User Data\Default] [mihcahmgecmbnbcchbopgniflfhgnkff] =>.Google Inc. {Verifier}
G2 - GCE: Preference [Pedro][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [Pedro][User Data\Default] [nnokjffnngdgfplfmimjioknefmkjfgc] Simet
G2 - GCE: Preference [Pedro][User Data\Default] [omghfjlpggmjjaagoclmmobgdodcjboh] Browsec VPN - Free and Unlimited VPN
G2 - GCE: Preference [Pedro][User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [Pedro][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (11) - 2s
P2 - EXT FILE: (.Microsoft Corporation - The plugin allows you to have a better expe.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npMeetingJoinPluginOC.dll =>.Microsoft Corporation®
P2 - EXT FILE: (.Bing.com.) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\bing.xml =>.Bing.com
P2 - EXT FILE: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\buscape.xml
P2 - EXT FILE: (.Unknown.) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - EXT FILE: (.Google Inc..) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml =>.Google Inc.
P2 - EXT FILE: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mercadolivre.xml
P2 - EXT FILE: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\twitter.xml
P2 - EXT FILE: (.Wikipedia.) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia-br.xml =>.Wikipedia
P2 - EXT FILE: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo-br.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} =>.Mozilla
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll =>.Adobe Systems Incorporated

---\ Internet Explorer, Arranque, Pesquisa, Phishing (15) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.br =>.Google Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navegador da Internet.) (11.00.16299.15 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\ INTERNET EXPLORER, site confiável e site sensível (2) - 0s
~ IE Restricted Site Good: hola.org
~ Microsoft Internet Explorer Restricted Site(s) Domains: 1(Good) / 0(Bad)

---\ Internet Explorer, Gestão do Proxy (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\ Análise das linhas, Carregamento Automático de programas (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\ Redireção do ficheiro Hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (28)

---\ Browser Helper Objects do navegador (5) - 0s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll =>.Tonec Inc.®
O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office\Office16\OCHelper.dll =>.Microsoft Corporation®
O2 - BHO: (no name) [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (.Orphan.)
O2 - BHO: Microsoft OneDrive for Business Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre-9.0.4\bin\jp2ssv.dll =>.Oracle America, Inc.®

---\ Atalhos globais Startup (201) - 20s
O4 - GS\Desktop [Administrador]: Benner Utilizados.lnk . (...) \\10.10.0.10\juridico\TI\benner\Benner\Utilizados
O4 - GS\Desktop [Administrador]: Itaú.lnk . (.Banco Itaú - Aplicativo Itaú.) C:\Users\Pedro\AppData\Local\Aplicativo Itau\itauaplicativo.exe {58F852EBA8EBE61A13F09288C4F1D562} =>.Banco Itaú
O4 - GS\Desktop [Administrador]: Limpeza de Cache.lnk . (.Microsoft Corporation - Processo de host do Windows (Rundll32).) C:\Windows\System32\rundll32.exe advapi32.dll,ProcessIdleTasks =>..Microsoft Corporation
O4 - GS\Desktop [Administrador]: Operacional - Vinhas Advogados - Atalho.lnk . (...) C:\Users\Pedro\vBox\Operacional - Vinhas Advogados
O4 - GS\Desktop [Administrador]: Remote Desktop Organizer.lnk . (...) C:\Program Files (x86)\Remote Desktop Organizer\RDO.exe
O4 - GS\Desktop [Administrador]: REMOTE.lnk . (.Microsoft Corporation - Assistência Remota do Windows.) C:\Windows\System32\msra.exe =>.Microsoft Corporation
O4 - GS\Desktop [Administrador]: TightVNC Viewer.lnk . (...) C:\WINDOWS\Installer\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}\viewer.ico
O4 - GS\Desktop [Administrador]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Desktop [Administrador]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Pedro\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrador]: DhcpExplorer.lnk . (.Nsasoft LLC. - DhcpExplorer.) C:\Program Files (x86)\Nsasoft\DhcpExplorer\DhcpExplorer.exe {50D95B1D70342FF9422CC45AD81ED7AC} =>.Nsasoft LLC.
O4 - GS\Quicklaunch [Administrador]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\Quicklaunch [Administrador]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrador]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrador]: KeePass 2.lnk . (.Dominik Reichl - KeePass.) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - GS\Quicklaunch [Administrador]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [Administrador]: Snagit 12.lnk . (.TechSmith Corporation - Snagit.) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [Administrador]: Wireshark.lnk . (.The Wireshark developer community, http://www.wiresha - Wireshark.) C:\Program Files (x86)\Wireshark\Wireshark.exe =>.Wireshark Foundation, Inc.®
O4 - GS\Quicklaunch [Administrador]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrador]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrador]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrador]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer GmbH®
O4 - GS\sendTo [Administrador]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrador]: 3CX Phone.lnk . (.3CX Ltd - 3CX VoIP Phone.) C:\Program Files (x86)\3CXPhone\3CXPhone.exe
O4 - GS\TaskBar [Administrador]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\TaskBar [Administrador]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrador]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrador]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrador]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Administrador]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\outicon.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrador]: RSA SecurID Token.lnk . (...) C:\Windows\Installer\{018A6880-5246-499D-A708-4A8B7B43A4B4}\ARPPRODUCTICON.exe
O4 - GS\TaskBar [Administrador]: Skype for Business 2015.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrador]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Desktop [Convidado]: Benner Utilizados.lnk . (...) \\10.10.0.10\juridico\TI\benner\Benner\Utilizados
O4 - GS\Desktop [Convidado]: Itaú.lnk . (.Banco Itaú - Aplicativo Itaú.) C:\Users\Pedro\AppData\Local\Aplicativo Itau\itauaplicativo.exe {58F852EBA8EBE61A13F09288C4F1D562} =>.Banco Itaú
O4 - GS\Desktop [Convidado]: Limpeza de Cache.lnk . (.Microsoft Corporation - Processo de host do Windows (Rundll32).) C:\Windows\System32\rundll32.exe advapi32.dll,ProcessIdleTasks =>..Microsoft Corporation
O4 - GS\Desktop [Convidado]: Operacional - Vinhas Advogados - Atalho.lnk . (...) C:\Users\Pedro\vBox\Operacional - Vinhas Advogados
O4 - GS\Desktop [Convidado]: Remote Desktop Organizer.lnk . (...) C:\Program Files (x86)\Remote Desktop Organizer\RDO.exe
O4 - GS\Desktop [Convidado]: REMOTE.lnk . (.Microsoft Corporation - Assistência Remota do Windows.) C:\Windows\System32\msra.exe =>.Microsoft Corporation
O4 - GS\Desktop [Convidado]: TightVNC Viewer.lnk . (...) C:\WINDOWS\Installer\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}\viewer.ico
O4 - GS\Desktop [Convidado]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Desktop [Convidado]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Pedro\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Convidado]: DhcpExplorer.lnk . (.Nsasoft LLC. - DhcpExplorer.) C:\Program Files (x86)\Nsasoft\DhcpExplorer\DhcpExplorer.exe {50D95B1D70342FF9422CC45AD81ED7AC} =>.Nsasoft LLC.
O4 - GS\Quicklaunch [Convidado]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\Quicklaunch [Convidado]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Convidado]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Convidado]: KeePass 2.lnk . (.Dominik Reichl - KeePass.) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - GS\Quicklaunch [Convidado]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [Convidado]: Snagit 12.lnk . (.TechSmith Corporation - Snagit.) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [Convidado]: Wireshark.lnk . (.The Wireshark developer community, http://www.wiresha - Wireshark.) C:\Program Files (x86)\Wireshark\Wireshark.exe =>.Wireshark Foundation, Inc.®
O4 - GS\Quicklaunch [Convidado]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Convidado]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Convidado]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Convidado]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer GmbH®
O4 - GS\sendTo [Convidado]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Convidado]: 3CX Phone.lnk . (.3CX Ltd - 3CX VoIP Phone.) C:\Program Files (x86)\3CXPhone\3CXPhone.exe
O4 - GS\TaskBar [Convidado]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\TaskBar [Convidado]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Convidado]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Convidado]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Convidado]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Convidado]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\outicon.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Convidado]: RSA SecurID Token.lnk . (...) C:\Windows\Installer\{018A6880-5246-499D-A708-4A8B7B43A4B4}\ARPPRODUCTICON.exe
O4 - GS\TaskBar [Convidado]: Skype for Business 2015.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation
O4 - GS\Programs [Convidado]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Desktop [Duda]: Benner Utilizados.lnk . (...) \\10.10.0.10\juridico\TI\benner\Benner\Utilizados
O4 - GS\Desktop [Duda]: Itaú.lnk . (.Banco Itaú - Aplicativo Itaú.) C:\Users\Pedro\AppData\Local\Aplicativo Itau\itauaplicativo.exe {58F852EBA8EBE61A13F09288C4F1D562} =>.Banco Itaú
O4 - GS\Desktop [Duda]: Limpeza de Cache.lnk . (.Microsoft Corporation - Processo de host do Windows (Rundll32).) C:\Windows\System32\rundll32.exe advapi32.dll,ProcessIdleTasks =>..Microsoft Corporation
O4 - GS\Desktop [Duda]: Operacional - Vinhas Advogados - Atalho.lnk . (...) C:\Users\Pedro\vBox\Operacional - Vinhas Advogados
O4 - GS\Desktop [Duda]: Remote Desktop Organizer.lnk . (...) C:\Program Files (x86)\Remote Desktop Organizer\RDO.exe
O4 - GS\Desktop [Duda]: REMOTE.lnk . (.Microsoft Corporation - Assistência Remota do Windows.) C:\Windows\System32\msra.exe =>.Microsoft Corporation
O4 - GS\Desktop [Duda]: TightVNC Viewer.lnk . (...) C:\WINDOWS\Installer\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}\viewer.ico
O4 - GS\Desktop [Duda]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Desktop [Duda]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Pedro\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Duda]: DhcpExplorer.lnk . (.Nsasoft LLC. - DhcpExplorer.) C:\Program Files (x86)\Nsasoft\DhcpExplorer\DhcpExplorer.exe {50D95B1D70342FF9422CC45AD81ED7AC} =>.Nsasoft LLC.
O4 - GS\Quicklaunch [Duda]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\Quicklaunch [Duda]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Duda]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Duda]: KeePass 2.lnk . (.Dominik Reichl - KeePass.) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - GS\Quicklaunch [Duda]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [Duda]: Snagit 12.lnk . (.TechSmith Corporation - Snagit.) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [Duda]: Wireshark.lnk . (.The Wireshark developer community, http://www.wiresha - Wireshark.) C:\Program Files (x86)\Wireshark\Wireshark.exe =>.Wireshark Foundation, Inc.®
O4 - GS\Quicklaunch [Duda]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Duda]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Duda]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Duda]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer GmbH®
O4 - GS\sendTo [Duda]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Duda]: 3CX Phone.lnk . (.3CX Ltd - 3CX VoIP Phone.) C:\Program Files (x86)\3CXPhone\3CXPhone.exe
O4 - GS\TaskBar [Duda]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\TaskBar [Duda]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Duda]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Duda]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Duda]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Duda]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\outicon.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Duda]: RSA SecurID Token.lnk . (...) C:\Windows\Installer\{018A6880-5246-499D-A708-4A8B7B43A4B4}\ARPPRODUCTICON.exe
O4 - GS\TaskBar [Duda]: Skype for Business 2015.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation
O4 - GS\Programs [Duda]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Desktop [Pedro]: Benner Utilizados.lnk . (...) \\10.10.0.10\juridico\TI\benner\Benner\Utilizados
O4 - GS\Desktop [Pedro]: Itaú.lnk . (.Banco Itaú - Aplicativo Itaú.) C:\Users\Pedro\AppData\Local\Aplicativo Itau\itauaplicativo.exe {58F852EBA8EBE61A13F09288C4F1D562} =>.Banco Itaú
O4 - GS\Desktop [Pedro]: Limpeza de Cache.lnk . (.Microsoft Corporation - Processo de host do Windows (Rundll32).) C:\Windows\System32\rundll32.exe advapi32.dll,ProcessIdleTasks =>..Microsoft Corporation
O4 - GS\Desktop [Pedro]: Operacional - Vinhas Advogados - Atalho.lnk . (...) C:\Users\Pedro\vBox\Operacional - Vinhas Advogados
O4 - GS\Desktop [Pedro]: Remote Desktop Organizer.lnk . (...) C:\Program Files (x86)\Remote Desktop Organizer\RDO.exe
O4 - GS\Desktop [Pedro]: REMOTE.lnk . (.Microsoft Corporation - Assistência Remota do Windows.) C:\Windows\System32\msra.exe =>.Microsoft Corporation
O4 - GS\Desktop [Pedro]: TightVNC Viewer.lnk . (...) C:\WINDOWS\Installer\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}\viewer.ico
O4 - GS\Desktop [Pedro]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Desktop [Pedro]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Pedro\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Pedro]: DhcpExplorer.lnk . (.Nsasoft LLC. - DhcpExplorer.) C:\Program Files (x86)\Nsasoft\DhcpExplorer\DhcpExplorer.exe {50D95B1D70342FF9422CC45AD81ED7AC} =>.Nsasoft LLC.
O4 - GS\Quicklaunch [Pedro]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\Quicklaunch [Pedro]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Pedro]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Pedro]: KeePass 2.lnk . (.Dominik Reichl - KeePass.) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - GS\Quicklaunch [Pedro]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [Pedro]: Snagit 12.lnk . (.TechSmith Corporation - Snagit.) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [Pedro]: Wireshark.lnk . (.The Wireshark developer community, http://www.wiresha - Wireshark.) C:\Program Files (x86)\Wireshark\Wireshark.exe =>.Wireshark Foundation, Inc.®
O4 - GS\Quicklaunch [Pedro]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Pedro]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Pedro]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Pedro]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer GmbH®
O4 - GS\sendTo [Pedro]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Pedro]: 3CX Phone.lnk . (.3CX Ltd - 3CX VoIP Phone.) C:\Program Files (x86)\3CXPhone\3CXPhone.exe
O4 - GS\TaskBar [Pedro]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\TaskBar [Pedro]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Pedro]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Pedro]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Pedro]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Pedro]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\outicon.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Pedro]: RSA SecurID Token.lnk . (...) C:\Windows\Installer\{018A6880-5246-499D-A708-4A8B7B43A4B4}\ARPPRODUCTICON.exe
O4 - GS\TaskBar [Pedro]: Skype for Business 2015.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation
O4 - GS\Programs [Pedro]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Desktop [WDAGUtilityAccount]: Benner Utilizados.lnk . (...) \\10.10.0.10\juridico\TI\benner\Benner\Utilizados
O4 - GS\Desktop [WDAGUtilityAccount]: Itaú.lnk . (.Banco Itaú - Aplicativo Itaú.) C:\Users\Pedro\AppData\Local\Aplicativo Itau\itauaplicativo.exe {58F852EBA8EBE61A13F09288C4F1D562} =>.Banco Itaú
O4 - GS\Desktop [WDAGUtilityAccount]: Limpeza de Cache.lnk . (.Microsoft Corporation - Processo de host do Windows (Rundll32).) C:\Windows\System32\rundll32.exe advapi32.dll,ProcessIdleTasks =>..Microsoft Corporation
O4 - GS\Desktop [WDAGUtilityAccount]: Operacional - Vinhas Advogados - Atalho.lnk . (...) C:\Users\Pedro\vBox\Operacional - Vinhas Advogados
O4 - GS\Desktop [WDAGUtilityAccount]: Remote Desktop Organizer.lnk . (...) C:\Program Files (x86)\Remote Desktop Organizer\RDO.exe
O4 - GS\Desktop [WDAGUtilityAccount]: REMOTE.lnk . (.Microsoft Corporation - Assistência Remota do Windows.) C:\Windows\System32\msra.exe =>.Microsoft Corporation
O4 - GS\Desktop [WDAGUtilityAccount]: TightVNC Viewer.lnk . (...) C:\WINDOWS\Installer\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}\viewer.ico
O4 - GS\Desktop [WDAGUtilityAccount]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Desktop [WDAGUtilityAccount]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Pedro\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [WDAGUtilityAccount]: DhcpExplorer.lnk . (.Nsasoft LLC. - DhcpExplorer.) C:\Program Files (x86)\Nsasoft\DhcpExplorer\DhcpExplorer.exe {50D95B1D70342FF9422CC45AD81ED7AC} =>.Nsasoft LLC.
O4 - GS\Quicklaunch [WDAGUtilityAccount]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [WDAGUtilityAccount]: KeePass 2.lnk . (.Dominik Reichl - KeePass.) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Snagit 12.lnk . (.TechSmith Corporation - Snagit.) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Wireshark.lnk . (.The Wireshark developer community, http://www.wiresha - Wireshark.) C:\Program Files (x86)\Wireshark\Wireshark.exe =>.Wireshark Foundation, Inc.®
O4 - GS\Quicklaunch [WDAGUtilityAccount]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [WDAGUtilityAccount]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [WDAGUtilityAccount]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [WDAGUtilityAccount]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer GmbH®
O4 - GS\sendTo [WDAGUtilityAccount]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [WDAGUtilityAccount]: 3CX Phone.lnk . (.3CX Ltd - 3CX VoIP Phone.) C:\Program Files (x86)\3CXPhone\3CXPhone.exe
O4 - GS\TaskBar [WDAGUtilityAccount]: eyeBeam.lnk . (...) C:\Program Files (x86)\CounterPath\eyeBeam 1.5\eyeBeam.exe
O4 - GS\TaskBar [WDAGUtilityAccount]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [WDAGUtilityAccount]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [WDAGUtilityAccount]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [WDAGUtilityAccount]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [WDAGUtilityAccount]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\outicon.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [WDAGUtilityAccount]: RSA SecurID Token.lnk . (...) C:\Windows\Installer\{018A6880-5246-499D-A708-4A8B7B43A4B4}\ARPPRODUCTICON.exe
O4 - GS\TaskBar [WDAGUtilityAccount]: Skype for Business 2015.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation
O4 - GS\Programs [WDAGUtilityAccount]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Advanced IP Scanner.lnk . (.Famatech Corp. - Advanced IP Scanner.) C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe =>.Famatech Corp.®
O4 - GS\CommonDesktop [Public]: OpenVPN GUI.lnk . (...) C:\Program Files\OpenVPN\bin\openvpn-gui.exe =>.OpenVPN Technologies, Inc.®
O4 - GS\CommonDesktop [Public]: Remote Computer Manager.lnk . (.S.K. Software - Remote Computer Manager.) C:\Program Files (x86)\Remote Computer Manager\RCM.exe =>.S.K. Software
O4 - GS\CommonDesktop [Public]: TeamViewer 13.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®
O4 - GS\CommonDesktop [Public]: vBox.lnk . (.eFolder - Sync Tool.) C:\Program Files (x86)\vBox\bin\agent_gui.exe --config 'C:\Program Files (x86)\vBox\conf\config.ini' {0664CADB13C394F908C7E2BDF7114CC6}
O4 - GS\Programs [Public]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\internet explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloco de notas.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Startup [Public]: Snagit 12.lnk . (.TechSmith Corporation - Snagit.) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe =>.TechSmith Corporation®
O4 - GS\Startup [Public]: vBox.lnk . (.eFolder - Sync Tool.) C:\Program Files (x86)\vBox\bin\agent_gui.exe --config 'C:\Program Files (x86)\vBox\conf\config.ini' {0664CADB13C394F908C7E2BDF7114CC6}
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Old Calculator.lnk . (.Microsoft Corporation - Calculadora do Windows.) C:\Windows\System32\calc1.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Conexão de Área de Trabalho Remota.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Ferramenta de Captura.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Gravador de Passos.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Aplicativo Wordpad do Windows.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visualizador XPS.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Mapa de caracteres.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Access 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\accicons.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Adobe Reader X.lnk . (...) C:\Windows\Installer\{AC76BA86-7AD7-1046-7B44-AA1000000001}\SC_Reader.ico =>.Adobe Inc.
O4 - GS\ProgramsCommon [Public]: Excel 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: KeePass 2.lnk . (.Dominik Reichl - KeePass.) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe =>.Open Source Developer, Dominik Reichl®
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: OneDrive for Business.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\grv_icons.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: OneNote 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\joticon.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\outicon.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: PowerPoint 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\pptico.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Publisher 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\pubs.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Skype for Business 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\lyncicon.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: TeamViewer 13.lnk . (.TeamViewer GmbH - TeamViewer 13.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®
O4 - GS\ProgramsCommon [Public]: Visio 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0051-0000-1000-0000000FF1CE}\visicon.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Wireshark.lnk . (.The Wireshark developer community, http://www.wiresha - Wireshark.) C:\Program Files (x86)\Wireshark\Wireshark.exe =>.Wireshark Foundation, Inc.®
O4 - GS\ProgramsCommon [Public]: Word 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-1000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation®

---\ Alteração Dominio/Clientes DNS (8) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = router6e0e64.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.10.0.9 =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{1d9c95e8-04e6-410e-a23e-5b8b9b371ea3}: NameServer = 208.67.222.222,208.67.220.220,8.8.8.8,8.8.4.4,209.244.0.3,209.244.0.4,4.2.2.1,4.2.2.2,4.2.2.3,4.2.2.4,4.2.2.5,4.2.2.6,189.38.95.95,189.38.95.96 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{972ec896-625e-4dcf-8aba-fad0adc03179}: NameServer = 208.67.222.222,208.67.220.220,8.8.8.8,8.8.4.4 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{1d9c95e8-04e6-410e-a23e-5b8b9b371ea3}: DhcpNameServer = 10.10.0.9 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{972ec896-625e-4dcf-8aba-fad0adc03179}: DhcpNameServer = 10.10.0.9 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{1d9c95e8-04e6-410e-a23e-5b8b9b371ea3}: DhcpDomain = router6e0e64.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{972ec896-625e-4dcf-8aba-fad0adc03179}: DhcpDomain = router6e0e64.com

---\ Protocolo adicional (27) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: mso-minsb.16 [64Bits] - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files\Microsoft Office\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: osf.16 [64Bits] - {5504BE45-A83B-4808-900A-3A5C36E7F77A} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files\Microsoft Office\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL =>.Microsoft Corporation®

---\ ASIC (ActiveSetup Installed Components) (5) - 1s
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitário de Instalação do Microsoft Windo.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\chrmstp.exe =>.Google Inc®

---\ Software instalados (86) - 20s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: 3CXPhone - (.3CX.) [HKLM][64Bits] -- {0DF8FA4D-299C-4250-9F09-C14E47E12224} =>.3CX
O42 - Logiciel: 7-Zip 16.04 (x64) - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip =>.Igor Pavlov
O42 - Logiciel: Adobe Flash Player 29 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 29 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Reader X (10.1.0) - Português - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1046-7B44-AA1000000001} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player =>.Adobe Systems, Inc.
O42 - Logiciel: Adobe Shockwave Player 12.3 - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {175D1C2E-CEF4-4909-901D-52AF3CD8ECD2} =>.Adobe Systems, Inc
O42 - Logiciel: Advanced IP Scanner 2.3 - (.Famatech.) [HKLM][64Bits] -- {0585FBE8-9244-4DA6-B3B9-1D912723E942} =>.Famatech
O42 - Logiciel: Advanced SystemCare 11 - (.IObit.) [HKLM][64Bits] -- Advanced SystemCare_is1 =>.IObit Information Technology®
O42 - Logiciel: Allgemeine Runtime Files (x86) - (.Sereby Corporation.) [HKLM][64Bits] -- {1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1 =>.Sereby Corporation
O42 - Logiciel: AnyToISO - (.CrystalIdea Software, Inc..) [HKLM][64Bits] -- AnyToISO_is1 =>.crystalidea.com®
O42 - Logiciel: Aplicativo Itaú - (.Banco Itaú.) [HKLM][64Bits] -- {D631AE49-0795-42CD-91C6-6078FB886DFD} =>.Banco Itaú
O42 - Logiciel: AWP 5.1.8 (64-bit) - (.Oberthur Technologies.) [HKLM][64Bits] -- {277A363F-17AC-4A2C-9A50-E0D2CBCF2117}
O42 - Logiciel: Backup and Sync from Google - (.Google, Inc..) [HKLM][64Bits] -- {4B7277C7-9CEE-45FC-B36B-19AD28281B9C} =>.Google, Inc.
O42 - Logiciel: Bullzip PDF Printer 11.5.0.2698 - (.Bullzip.) [HKLM][64Bits] -- Bullzip PDF Printer_is1 =>.Bullzip
O42 - Logiciel: Cobian Backup 11 Gravity - (.CobianSoft, Luis Cobian.) [HKLM][64Bits] -- CobBackup11 =>.CobianSoft, Luis Cobian
O42 - Logiciel: CutePDF Writer 2.8 - (..) [HKLM][64Bits] -- CutePDF Writer Installation =>.Acro Software Inc.®
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated
O42 - Logiciel: DFX - (.Power Technology.) [HKLM][64Bits] -- DFX =>.Power Technology
O42 - Logiciel: DhcpExplorer 1.4.8 - (.Nsasoft LLC..) [HKLM][64Bits] -- DhcpExplorer_is1 =>.Nsasoft LLC.
O42 - Logiciel: DirectX 9.0c Extra Files (x86, x64) - (.Sereby Corporation.) [HKLM][64Bits] -- {8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1 =>.Sereby Corporation
O42 - Logiciel: doPDF 7.1 printer - (.Softland.) [HKLM][64Bits] -- doPDF 7 printer_is1 =>.Softland
O42 - Logiciel: ESET Smart Security - (.ESET, spol. s r.o..) [HKLM][64Bits] -- {61F133C4-BB14-432A-AF88-1B86C68850AA} =>.ESET, spol. s r.o.
O42 - Logiciel: eyeBeam 1.5.7 - (..) [HKLM][64Bits] -- eyeBeam_is1
O42 - Logiciel: Giesecke & Devrient GmbH StarSign CUT - (.Giesecke & Devrient GmbH.) [HKLM][64Bits] -- {F24F876B-7D71-4BD6-88E9-614D3BB84217}
O42 - Logiciel: Giesecke & Devrient GmbH StarSign CUT - (.Giesecke & Devrient GmbH.) [HKLM][64Bits] -- SZCCID
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Chrome Canary - (.Google Inc..) [HKCU][64Bits] -- Google Chrome SxS =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager =>.Tonec Inc.®
O42 - Logiciel: IObit Unlocker - (.IObit.) [HKLM][64Bits] -- IObit Unlocker_is1 =>.IObit Information Technology®
O42 - Logiciel: Java 8 Update 144 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F32180144F0} =>.Oracle Corporation
O42 - Logiciel: Java 8 Update 144 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F64180144F0} =>.Oracle Corporation
O42 - Logiciel: Java 9.0.4 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {885A3911-0760-5252-92C2-001B92997DEA} =>.Oracle Corporation
O42 - Logiciel: KeePass Password Safe 2.38 - (.Dominik Reichl.) [HKLM][64Bits] -- KeePassPasswordSafe2_is1 =>.Dominik Reichl
O42 - Logiciel: KMSpico - (..) [HKLM][64Bits] -- {8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>HackTool.KMSpico
O42 - Logiciel: Lazesoft Recovery Suite version 4.0 Unlimited Edition - (.Lazesoft.) [HKLM][64Bits] -- LS-32CB12D5-CC47-4BC8-BC97-0613CDCB0406_is1 =>.LAZYSOFT TECHNIQUE LTD®
O42 - Logiciel: Microsoft Access MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0015-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft DCF MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0090-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0016-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Groove MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00BA-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft InfoPath MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0044-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft OneNote MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00A1-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Outlook MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001A-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft PowerPoint MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0018-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Publisher MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0019-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Skype for Business MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-012B-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visio MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0054-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visio Professional 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0051-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visio Professional 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office16.VISPRO =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Word MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001B-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Mozilla Firefox 33.1 (x86 pt-BR) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 33.1 (x86 pt-BR) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Mozilla Thunderbird 52.6.0 (x86 pt-BR) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Thunderbird 52.6.0 (x86 pt-BR) =>.Mozilla Corporation®
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM][64Bits] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B} =>.Nero AG
O42 - Logiciel: Notepad++ (32-bit x86) - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ =>.Notepad++ Team
O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-007E-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0416-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Old Calculator for Windows 10 - (.http://winaero.com.) [HKLM][64Bits] -- OldCalcForWin10 =>.http://winaero.com
O42 - Logiciel: OpenVPN 2.3.18-I602 - (.OpenVPN Technologie.) [HKLM][64Bits] -- OpenVPN =>.OpenVPN Technologie
O42 - Logiciel: Remote Computer Manager by casper03 version 6.0.7 - (.S.K. Software.) [HKLM][64Bits] -- Remote Computer Manager by casper03_is1 =>.S.K. Software
O42 - Logiciel: Remote Desktop Organizer - (.Appmazing.) [HKLM][64Bits] -- Remote Desktop Organizer
O42 - Logiciel: RSA SecurID Software Token with Automation - (.EMC Corporation.) [HKLM][64Bits] -- {018A6880-5246-499D-A708-4A8B7B43A4B4} =>.EMC Corporation
O42 - Logiciel: Skype for Business Basic 2015 - pt-br - (.Microsoft Corporation.) [HKLM][64Bits] -- LyncEntryRetail - pt-br =>.Microsoft Corporation®
O42 - Logiciel: Snagit 12 - (.TechSmith Corporation.) [HKLM][64Bits] -- {ae5218bf-cfcc-4099-818d-7e16ce0d97df} =>.TechSmith Corporation®
O42 - Logiciel: Snagit 12 - (.TechSmith Corporation.) [HKLM][64Bits] -- {BDFD9ADC-3F97-4A8A-A533-987B21776449} =>.TechSmith Corporation
O42 - Logiciel: StartIsBack++ - (.startisback.com.) [HKLM][64Bits] -- StartIsBack =>.startisback.com
O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} =>.Adobe Systems, Inc
O42 - Logiciel: TAP-Windows 9.21.2 - (.OpenVPN Technologie.) [HKLM][64Bits] -- TAP-Windows =>.OpenVPN Technologie
O42 - Logiciel: TeamViewer 13 - (.TeamViewer.) [HKLM][64Bits] -- TeamViewer =>.TeamViewer GmbH®
O42 - Logiciel: TeraCopy version 3.2 - (.Code Sector.) [HKLM][64Bits] -- TeraCopy_is1 =>.Code Sector®
O42 - Logiciel: TightVNC - (.GlavSoft LLC..) [HKLM][64Bits] -- {D2372F87-7DA2-47F7-A102-AF2181B8EAA2} =>.GlavSoft LLC.
O42 - Logiciel: Update for Skype for Business 2016 (KB3115087) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4} =>.Microsoft Corporation®
O42 - Logiciel: Update for Skype for Business 2016 (KB3115087) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4} =>.Microsoft Corporation®
O42 - Logiciel: Update for Skype for Business 2016 (KB3115087) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-00C1-0000-1000-0000000FF1CE}_Office16.VISPRO_{C48D0508-2A21-42EA-8BC9-D387768F54F4} =>.Microsoft Corporation®
O42 - Logiciel: Update for Skype for Business 2016 (KB3115087) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-012B-0416-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4} =>.Microsoft Corporation®
O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4023057) - (.Microsoft Corporation.) [HKLM][64Bits] -- {AC0D130B-8809-4125-811F-667893B90644} =>.Microsoft Corporation
O42 - Logiciel: vBox - (.Penso Tecnologia.) [HKLM][64Bits] -- vBox 2.5.4.1070
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: VSDC Free Video Editor version 5.8.6.806 - (.Flash-Integro LLC.) [HKLM][64Bits] -- VSDC Free Video Editor_is1 =>.Vector Ltd.®
O42 - Logiciel: WinPcap 4.1.3 - (.Riverbed Technology, Inc..) [HKLM][64Bits] -- WinPcapInst =>.Riverbed Technology, Inc.
O42 - Logiciel: WinRAR 5.50 beta 4 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: Wireshark 2.4.5 32-bit - (.The Wireshark developer community, https://www.wireshark.org.) [HKLM][64Bits] -- Wireshark =>.Wireshark Foundation, Inc.®

---\ HKCU & HKLM Software Keys (148) - 20s
HKLM\SOFTWARE\3CXPhone
HKLM\SOFTWARE\Acro Software Inc =>.Acro Software Inc
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKLM\SOFTWARE\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Caphyon =>.Caphyon
HKLM\SOFTWARE\CobianSoft =>.CobianSoft, Luis Cobian
HKLM\SOFTWARE\DFX =>.DFX Power Technology
HKLM\SOFTWARE\ESET =>.ESET
HKLM\SOFTWARE\famatech =>.Famatech
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\GPL Ghostscript =>.GPL Ghostscript
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Internet Download Manager =>.Tonec Inc
HKLM\SOFTWARE\IObit =>.IObit
HKLM\SOFTWARE\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Lazesoft =>.Lazesoft
HKLM\SOFTWARE\LogMeIn Rescue =>.LogMeIn Entreprise
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Nero =>.Ahead Corporation
HKLM\SOFTWARE\Notepad++ =>.Don Ho
HKLM\SOFTWARE\Oberthur Technologies
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Oracle =>.Oracle
HKLM\SOFTWARE\PowerPivot =>.PowerPivot
HKLM\SOFTWARE\PowerTechnology =>.PowerTechnology
HKLM\SOFTWARE\ProcessLasso =>.Bitsum Technologies
HKLM\SOFTWARE\qubnfe
HKLM\SOFTWARE\RemoteComputerManager
HKLM\SOFTWARE\RSA =>.RSA Security
HKLM\SOFTWARE\RSA Security =>.RSA Security
HKLM\SOFTWARE\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\TechSmith =>.TechSmith
HKLM\SOFTWARE\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WinPcap =>.Riverbed Technology
HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\3CXPhone
HKLM\SOFTWARE\WOW6432Node\Acro Software Inc =>.Acro Software Inc
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\AppDataLow =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\WOW6432Node\Caphyon =>.Caphyon
HKLM\SOFTWARE\WOW6432Node\CobianSoft =>.CobianSoft, Luis Cobian
HKLM\SOFTWARE\WOW6432Node\DFX =>.DFX Power Technology
HKLM\SOFTWARE\WOW6432Node\ESET =>.ESET
HKLM\SOFTWARE\WOW6432Node\famatech =>.Famatech
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\GPL Ghostscript =>.GPL Ghostscript
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Internet Download Manager =>.Tonec Inc
HKLM\SOFTWARE\WOW6432Node\IObit =>.IObit
HKLM\SOFTWARE\WOW6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\WOW6432Node\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\WOW6432Node\Lazesoft =>.Lazesoft
HKLM\SOFTWARE\WOW6432Node\LogMeIn Rescue =>.LogMeIn Entreprise
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\Nero =>.Ahead Corporation
HKLM\SOFTWARE\WOW6432Node\Notepad++ =>.Don Ho
HKLM\SOFTWARE\WOW6432Node\Oberthur Technologies
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\Oracle =>.Oracle
HKLM\SOFTWARE\WOW6432Node\PowerPivot =>.PowerPivot
HKLM\SOFTWARE\WOW6432Node\PowerTechnology =>.PowerTechnology
HKLM\SOFTWARE\WOW6432Node\ProcessLasso =>.Bitsum Technologies
HKLM\SOFTWARE\WOW6432Node\qubnfe
HKLM\SOFTWARE\WOW6432Node\RemoteComputerManager
HKLM\SOFTWARE\WOW6432Node\RSA =>.RSA Security
HKLM\SOFTWARE\WOW6432Node\RSA Security =>.RSA Security
HKLM\SOFTWARE\WOW6432Node\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\WOW6432Node\TechSmith =>.TechSmith
HKLM\SOFTWARE\WOW6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\WOW6432Node\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\WinPcap =>.Riverbed Technology
HKLM\SOFTWARE\WOW6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\3CX =>.3CX
HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\Akeo Consulting =>.Akeo Consulting
HKCU\SOFTWARE\Aplicativo Itau
HKCU\SOFTWARE\Apowersoft =>.Apowersoft
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKCU\SOFTWARE\Canon =>.Canon
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Code Sector =>.Code Sector
HKCU\SOFTWARE\CounterPath =>.CounterPath
HKCU\SOFTWARE\CrystalIdea Software =>.CrystalIdea Software
HKCU\SOFTWARE\DFX =>.DFX Power Technology
HKCU\SOFTWARE\DivXNetworks =>.DivXNetworks
HKCU\SOFTWARE\DownloadManager =>.DownloadManager
HKCU\SOFTWARE\ESET =>.ESET
HKCU\SOFTWARE\famatech =>.Famatech
HKCU\SOFTWARE\FlashIntegro =>.Flash-Integro
HKCU\SOFTWARE\ForensiT
HKCU\SOFTWARE\GbPlugin =>.GAS Tecnologia
HKCU\SOFTWARE\GlavSoft LLC. =>.GlavSoft LLC.
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\GRETECH =>.Gretech
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\IObit =>.IObit
HKCU\SOFTWARE\Jabra =>.Jabra
HKCU\SOFTWARE\Lazesoft =>.Lazesoft
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\Nero =>.Ahead Corporation
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Norassie =>.Norassie
HKCU\SOFTWARE\Northcode Inc =>.Northcode Inc
HKCU\SOFTWARE\Oberthur Technologies
HKCU\SOFTWARE\Obsidium
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\PowerTechnology =>.PowerTechnology
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\qubnfe
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Remote Desktop Organizer
HKCU\SOFTWARE\RemoteComputerManager
HKCU\SOFTWARE\RSA =>.RSA Security
HKCU\SOFTWARE\Softland =>.Softland
HKCU\SOFTWARE\SoftPerfect =>.SoftPerfect
HKCU\SOFTWARE\StartIsBack =>.StartIsBack.com
HKCU\SOFTWARE\Synaptics =>.Synaptics
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\TeamViewer =>.TeamViewer
HKCU\SOFTWARE\TechSmith =>.TechSmith
HKCU\SOFTWARE\Thunderbird =>.Thunderbird
HKCU\SOFTWARE\TightVNC =>.TightVNC Project
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\Wireshark =>.Wireshark
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow\Software\Macromedia =>.Macromedia

---\ Conteúdo das pastas Programs (302) - 12s
O43 - CFD: 07/03/2018 - [] D -- C:\Program Files\7-Zip =>.Igor Pavlov
O43 - CFD: 28/06/2017 - [0] SHD -- C:\Program Files\Arquivos Comuns =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\Program Files\Bullzip =>.Bullzip
O43 - CFD: 22/03/2018 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files\ESET =>.ESET, spol. s r.o.®
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files\FlashIntegro =>.Flash-Integro LLC
O43 - CFD: 29/03/2018 - [] D -- C:\Program Files\Google =>.Google Inc®
O43 - CFD: 23/03/2018 - [] D -- C:\Program Files\Hola =>PUP.Optional.HolaSearch =>PUP.Optional.HolaSearch
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files\HP =>.Hewlett-Packard
O43 - CFD: 09/02/2018 - [] D -- C:\Program Files\IDT =>.IDT
O43 - CFD: 09/02/2018 - [] D -- C:\Program Files\internet explorer =>.Microsoft Corporation
O43 - CFD: 12/03/2018 - [] D -- C:\Program Files\Java =>.Oracle
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files\KMSpico =>HackTool.KMSpico
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] AD -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [] AD -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\Program Files\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files\Oberthur Technologies {2DD0195E4C2A2BB2DD729803591178E7}
O43 - CFD: 01/03/2018 - [] D -- C:\Program Files\OpenVPN =>.OpenVPN Technologie
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files\rempl =>.Microsoft Corporation®
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files\RSA SecurID Software Token =>.RSA Security
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files\RSA SecurID Token Common =>.RSA Security
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files\Softland =>.Softland®
O43 - CFD: 09/02/2018 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated®
O43 - CFD: 01/03/2018 - [] D -- C:\Program Files\TAP-Windows =>.OpenVPN Technologie
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files\TeraCopy =>.Code Sector Inc.
O43 - CFD: 09/02/2018 - [] D -- C:\Program Files\TightVNC =>.TightVNC Project
O43 - CFD: 28/06/2017 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files\windows nt =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 06/04/2018 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 02/04/2018 - [] D -- C:\Program Files (x86)\3CXPhone
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\Acro Software =>.Acro Software
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files (x86)\Advanced IP Scanner =>.Famatech Corp.
O43 - CFD: 07/03/2018 - [] D -- C:\Program Files (x86)\AnyToISO =>.Crystal Idea
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files (x86)\Apowersoft =>.Apowersoft
O43 - CFD: 06/04/2018 - [] D -- C:\Program Files (x86)\Cobian Backup 11 =>.CobianSoft, Luis Cobian
O43 - CFD: 12/03/2018 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 20/03/2018 - [] D -- C:\Program Files (x86)\CounterPath =>.CounterPath
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files (x86)\DFX =>.DFX Power Technology
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files (x86)\G&D
O43 - CFD: 28/06/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\GPLGS =>.Ghostscript Team
O43 - CFD: 28/06/2017 - [] D -- C:\Program Files (x86)\GUM1669.tmp =>.Google Inc®
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\Internet Download Manager =>.Tonec Inc
O43 - CFD: 09/02/2018 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\IObit =>.IObit
O43 - CFD: 12/03/2018 - [] D -- C:\Program Files (x86)\Java =>.Oracle
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files (x86)\KeePass Password Safe 2 =>.Open Source Developer, Dominik Reichl®
O43 - CFD: 20/02/2018 - [] AD -- C:\Program Files (x86)\Lazesoft Recovery Suite =>.Lazesoft
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\Program Files (x86)\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files (x86)\Mozilla Thunderbird =>.Mozilla
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\Program Files (x86)\Notepad++ =>.Don Ho
O43 - CFD: 21/02/2018 - [] D -- C:\Program Files (x86)\Nsasoft =>.NsaSoft
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\Oberthur Technologies {2DD0195E4C2A2BB2DD729803591178E7}
O43 - CFD: 27/03/2018 - [0] SHD -- C:\Program Files (x86)\qubnfe
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files (x86)\Remote Computer Manager
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\Remote Desktop Organizer
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\RSA SecurID Software Token =>.RSA Security
O43 - CFD: 07/02/2018 - [] AD -- C:\Program Files (x86)\RSA SecurID Token Common =>.RSA Security
O43 - CFD: 28/06/2017 - [] AD -- C:\Program Files (x86)\StartIsBack =>.StartCom
O43 - CFD: 29/03/2018 - [] D -- C:\Program Files (x86)\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\TechSmith =>.TechSmith
O43 - CFD: 06/02/2018 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 12/03/2018 - [] AD -- C:\Program Files (x86)\vBox =>.Vmedia
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\windows nt =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files (x86)\WinPcap =>.Riverbed Technology
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files (x86)\Wireshark =>.Wireshark
O43 - CFD: 02/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3CX Phone
O43 - CFD: 07/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
O43 - CFD: 29/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 14/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced IP Scanner v2 =>.Famatech Corp.
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare =>.IObit
O43 - CFD: 07/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyToISO =>.Crystal Idea
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AWP
O43 - CFD: 29/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip =>.Bullzip
O43 - CFD: 20/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CounterPath =>.CounterPath
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF =>.Acro Software Inc.
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer =>.DFX Audio Enhancer
O43 - CFD: 21/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DhcpExplorer
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\doPDF 7
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET =>.ESET
O43 - CFD: 20/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office 2016 =>.Microsoft Corporation
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashIntegro =>.Flash-Integro LLC
O43 - CFD: 27/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InterApp Control
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Unlocker =>.IObit
O43 - CFD: 12/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lazesoft Recovery Suite =>.Lazesoft
O43 - CFD: 29/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ =>.Don Ho
O43 - CFD: 01/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN =>.OpenVPN Technologie
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Computer Manager
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Desktop Organizer
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RSA =>.RSA Security
O43 - CFD: 02/04/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 14/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 01/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows =>.OpenVPN Technologie
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith =>.TechSmith
O43 - CFD: 09/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TightVNC =>.TightVNC Project
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vBox =>.Vmedia
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap =>.Riverbed Technology
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 29/03/2018 - [] D -- C:\ProgramData\3CXPhone for Windows
O43 - CFD: 06/02/2018 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\Apowersoft =>.Apowersoft
O43 - CFD: 29/03/2018 - [] D -- C:\ProgramData\Caphyon =>.Caphyon
O43 - CFD: 28/06/2017 - [0] SHD -- C:\ProgramData\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [0] SHD -- C:\ProgramData\Documentos =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\ProgramData\ESET =>.ESET
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\FlashIntegro =>.Flash-Integro LLC
O43 - CFD: 06/02/2018 - [0] D -- C:\ProgramData\IDM =>.IDM
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\IObit =>.IObit
O43 - CFD: 28/06/2017 - [0] SHD -- C:\ProgramData\Menu Iniciar =>.Microsoft Corporation
O43 - CFD: 20/03/2018 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/03/2018 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\ProgramData\Microsoft Toolkit =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [0] SHD -- C:\ProgramData\Modelos =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 12/03/2018 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\PDF Writer =>.Acro Software
O43 - CFD: 03/04/2018 - [] D -- C:\ProgramData\ProductData =>.Microsoft Corporation
O43 - CFD: 20/03/2018 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] AD -- C:\ProgramData\regid.1995-08.com.techsmith =>.TechSmith Corporation
O43 - CFD: 19/02/2018 - [] D -- C:\ProgramData\RSA =>.RSA Security
O43 - CFD: 29/09/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\ProgramData\SZCCID
O43 - CFD: 06/02/2018 - [] D -- C:\ProgramData\TechSmith =>.TechSmith
O43 - CFD: 09/02/2018 - [0] D -- C:\ProgramData\TightVNC =>.TightVNC Project
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\ProgramData\{13CFD044-61E4-4EAC-AD61-02536D961216}
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 06/02/2018 - [] D -- C:\Program Files (x86)\Common Files\DFX =>.DFX Power Technology
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files (x86)\Common Files\FlashIntegro =>.Flash-Integro LLC
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files (x86)\Common Files\IObit =>.IObit
O43 - CFD: 18/03/2018 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Common Files\system =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] AD -- C:\Program Files (x86)\Common Files\TechSmith Shared =>.TechSmith
O43 - CFD: 29/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\3CXPhone for Windows
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 02/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Apowersoft =>.Apowersoft
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\DMCache =>.DMCache
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\ESET =>.ESET
O43 - CFD: 02/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\FlashIntegro =>.Flash-Integro LLC
O43 - CFD: 05/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Google =>.Google
O43 - CFD: 23/03/2018 - [0] D -- C:\Users\Pedro\AppData\Roaming\Hola =>PUP.Optional.HolaSearch
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\IDM =>.IDM
O43 - CFD: 08/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\IObit =>.IObit
O43 - CFD: 04/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\KeePass =>.KeePass
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 21/02/2018 - [] SD -- C:\Users\Pedro\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Notepad++ =>.Don Ho
O43 - CFD: 06/02/2018 - [] HD -- C:\Users\Pedro\AppData\Roaming\Obsidium =>.Game
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\PCProtect =>.SUP.PCProtect
O43 - CFD: 22/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\PDF Writer =>.Acro Software
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Skype =>.Skype
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Softland =>.Softland
O43 - CFD: 12/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 21/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 03/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\TeraCopy =>.Code Sector Inc.
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Thunderbird =>.Thunderbird
O43 - CFD: 09/02/2018 - [0] D -- C:\Users\Pedro\AppData\Roaming\TightVNC =>.TightVNC Project
O43 - CFD: 23/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\uTorrent
O43 - CFD: 03/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 02/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Wireshark =>.Wireshark
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 02/04/2018 - [] D -- C:\Users\Pedro\AppData\Local\3CX VoIP Phone
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Adobe =>.Adobe
O43 - CFD: 29/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\AdvinstAnalytics =>.SUP.Various
O43 - CFD: 01/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\Aplicativo Itau
O43 - CFD: 29/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\ASP.NET
O43 - CFD: 14/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\CEF =>.CEF
O43 - CFD: 23/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\Chromium =>.Chromium
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 20/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\CounterPath =>.CounterPath
O43 - CFD: 18/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\CrashRpt
O43 - CFD: 08/02/2018 - [0] SHD -- C:\Users\Pedro\AppData\Local\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [0] D -- C:\Users\Pedro\AppData\Local\DBG =>.DBG
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\DFX =>.DFX Power Technology
O43 - CFD: 03/04/2018 - [] D -- C:\Users\Pedro\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\ESET =>.ESET
O43 - CFD: 29/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\Google =>.Google
O43 - CFD: 08/02/2018 - [0] SHD -- C:\Users\Pedro\AppData\Local\Histórico =>.Microsoft Corporation
O43 - CFD: 12/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 22/03/2018 - [0] D -- C:\Users\Pedro\AppData\Local\Notepad++ =>.Don Ho
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\PDF Writer =>.Acro Software
O43 - CFD: 06/02/2018 - [0] D -- C:\Users\Pedro\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 02/03/2018 - [0] D -- C:\Users\Pedro\AppData\Local\PlaceholderTileLogoFolder
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\RDO
O43 - CFD: 19/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\RSA =>.RSA Security
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\StartIsBack =>.StartCom
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\TechSmith =>.TechSmith
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [0] SHD -- C:\Users\Pedro\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\Thunderbird =>.Thunderbird
O43 - CFD: 08/02/2018 - [] D -- C:\Users\Pedro\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 27/03/2018 - [] D -- C:\Users\Pedro\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 06/02/2018 - [0] D -- C:\Users\Pedro\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\LocalLow\Adobe =>.Adobe
O43 - CFD: 07/02/2018 - [] D -- C:\Users\Pedro\AppData\LocalLow\IObit =>.IObit
O43 - CFD: 06/02/2018 - [] SD -- C:\Users\Pedro\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2018 - [0] D -- C:\Users\Pedro\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 06/02/2018 - [] D -- C:\Users\Pedro\AppData\LocalLow\Sun =>.Oracle
O43 - CFD: 23/03/2018 - [] D -- C:\Users\Pedro\Desktop\InterApp Control
O43 - CFD: 15/03/2018 - [] RD -- C:\Users\Pedro\Desktop\Music
O43 - CFD: 22/03/2018 - [] D -- C:\Users\Pedro\Desktop\Projeto Cabeamento Estruturado
O43 - CFD: 20/03/2018 - [] D -- C:\Users\Pedro\Desktop\VOIP
O43 - CFD: 29/09/2017 - [] RD -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] RD -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/03/2018 - [] RD -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 01/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativo Itaú
O43 - CFD: 05/03/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativos Canary do Google Chrome
O43 - CFD: 08/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativos do Google Chrome
O43 - CFD: 06/04/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cobian Backup 11 =>.CobianSoft, Luis Cobian
O43 - CFD: 08/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc
O43 - CFD: 29/09/2017 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 14/03/2018 - [] RD -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] RD -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] RD -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [] D -- C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 28/06/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Histórico =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 28/06/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Histórico =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/02/2018 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 18/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 12/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DataSharing =>.DataSharing
O43 - CFD: 13/03/2018 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DBG =>.DBG
O43 - CFD: 12/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\ESET =>.ESET
O43 - CFD: 14/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 06/04/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 12/03/2018 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 02/04/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\speech =>.Microsoft Corporation
O43 - CFD: 13/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\TokenBroker
O43 - CFD: 08/02/2018 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\IObit =>.IObit
O43 - CFD: 13/03/2018 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 02/04/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Softland =>.Softland

---\ ShellIconOverlayIdentifiers (SIOI) (14) - 1s
O106 - SIOI: [ AnchorOverlayAttention] - {40D1DAA7-9CB5-4DB7-8610-A814EDB003A5}. (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O106 - SIOI: [ AnchorOverlayLockedSynced] - {5B05543A-73D8-4D80-97F9-13F471224DD8}. (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O106 - SIOI: [ AnchorOverlayLockedSyncing] - {1C514AC9-A6B4-4692-A18E-9A2EE0B4E277}. (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O106 - SIOI: [ AnchorOverlaySynced] - {56E89524-684C-4352-B350-F97A7377DD64}. (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O106 - SIOI: [ AnchorOverlaySyncing] - {C6B3FD8D-C629-4A7F-AF73-9ABB59AF029D}. (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O106 - SIOI: [ GoogleDriveBlacklisted] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}. (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\googledrivesync64.dll =>.Google Inc®
O106 - SIOI: [ GoogleDriveSynced] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}. (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\googledrivesync64.dll =>.Google Inc®
O106 - SIOI: [ GoogleDriveSyncing] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}. (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\googledrivesync64.dll =>.Google Inc®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL de Extensão do Shell do Armazenamento A.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: [IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll =>.Tonec Inc.®
O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - Interface de usuário de cache do cliente.) -- C:\WINDOWS\System32\cscui.dll =>.Microsoft Corporation

---\ Search Context Menu Handlers (SCMH) (51) - 5s
O108 - CMH1: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll =>.Igor Pavlov
O108 - CMH1: Advanced SystemCare [64Bits] - {2803063F-4B8D-4dc6-8874-D1802487FE2D} . (.IObit - ASCExtMenu Module.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll =>.IObit Information Technology®
O108 - CMH1: ANotepad++64 [64Bits] - {B298D29A-A6ED-11DE-BA8C-A68E55D89593} . (. - ShellHandler for Notepad++ (64 bit).) -- C:\Program Files (x86)\Notepad++\NppShell_06.dll =>.Notepad++®
O108 - CMH1: ESET Smart Security - Context Menu Shell Extension [64Bits] - {B089FE88-FB52-11D3-BDF1-0050DA34150D} . (.ESET - ESET Shell Extension.) -- C:\Program Files\ESET\ESET Security\shellExt.dll =>.ESET, spol. s r.o.®
O108 - CMH1: GDContextMenu [64Bits] - {BB02B294-8425-42E5-983F-41A1FA970CD6} . (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\contextmenu64.dll =>.Google Inc®
O108 - CMH1: ModernSharing [64Bits] - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: SnagItMainShellExt [64Bits] - {CF74B903-3389-469c-B3B6-0204D204FCBD} . (.TechSmith Corporation - Snagit Shell Extension DLL.) -- C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll =>.TechSmith Corporation®
O108 - CMH1: SyncedToolExt [64Bits] - {113D0AEB-22E4-419D-B746-319FCAF60456} . (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O108 - CMH1: TeraCopy [64Bits] - {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} . (...) -- C:\Program Files\TeraCopy\TeraCopyExt.dll =>.Code Sector®
O108 - CMH1: UnLockerMenu [64Bits] - {410BF280-86EF-4E0F-8279-EC5848546AD3} . (.IObit - IObitUnlockerExtension.) -- C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll =>.IObit Information Technology®
O108 - CMH1: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH1: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.)
O108 - CMH1: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation
O108 - CMH2: Advanced SystemCare [64Bits] - {2803063F-4B8D-4dc6-8874-D1802487FE2D} . (.IObit - ASCExtMenu Module.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll =>.IObit Information Technology®
O108 - CMH2: ESET Smart Security - Context Menu Shell Extension [64Bits] - {B089FE88-FB52-11D3-BDF1-0050DA34150D} . (.ESET - ESET Shell Extension.) -- C:\Program Files\ESET\ESET Security\shellExt.dll =>.ESET, spol. s r.o.®
O108 - CMH2: GDContextMenu [64Bits] - {BB02B294-8425-42E5-983F-41A1FA970CD6} . (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\contextmenu64.dll =>.Google Inc®
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH2: TeraCopy [64Bits] - {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} . (...) -- C:\Program Files\TeraCopy\TeraCopyExt.dll =>.Code Sector®
O108 - CMH2: UnLockerMenu [64Bits] - {410BF280-86EF-4E0F-8279-EC5848546AD3} . (.IObit - IObitUnlockerExtension.) -- C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll =>.IObit Information Technology®
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH4: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll =>.Igor Pavlov
O108 - CMH4: Advanced SystemCare [64Bits] - {2803063F-4B8D-4dc6-8874-D1802487FE2D} . (.IObit - ASCExtMenu Module.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll =>.IObit Information Technology®
O108 - CMH4: GDContextMenu [64Bits] - {BB02B294-8425-42E5-983F-41A1FA970CD6} . (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\contextmenu64.dll =>.Google Inc®
O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Interface de usuário de cache do cliente.) -- C:\WINDOWS\System32\cscui.dll =>.Microsoft Corporation
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH4: SnagItMainShellExt [64Bits] - {CF74B903-3389-469c-B3B6-0204D204FCBD} . (.TechSmith Corporation - Snagit Shell Extension DLL.) -- C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll =>.TechSmith Corporation®
O108 - CMH4: SyncedToolExt [64Bits] - {113D0AEB-22E4-419D-B746-319FCAF60456} . (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O108 - CMH4: TeraCopy [64Bits] - {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} . (...) -- C:\Program Files\TeraCopy\TeraCopyExt.dll =>.Code Sector®
O108 - CMH4: UnLockerMenu [64Bits] - {410BF280-86EF-4E0F-8279-EC5848546AD3} . (.IObit - IObitUnlockerExtension.) -- C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll =>.IObit Information Technology®
O108 - CMH4: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH5: SyncedToolExt [64Bits] - {113D0AEB-22E4-419D-B746-319FCAF60456} . (.eFolder - Sync Shell Extension.) -- C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll {0664CADB13C394F908C7E2BDF7114CC6}
O108 - CMH5: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation
O108 - CMH6: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll =>.Igor Pavlov
O108 - CMH6: ESET Smart Security - Context Menu Shell Extension [64Bits] - {B089FE88-FB52-11D3-BDF1-0050DA34150D} . (.ESET - ESET Shell Extension.) -- C:\Program Files\ESET\ESET Security\shellExt.dll =>.ESET, spol. s r.o.®
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Interface de usuário de cache do cliente.) -- C:\WINDOWS\System32\cscui.dll =>.Microsoft Corporation
O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - Resolvedor de Aplicativos.) -- C:\Windows\System32\appresolver.dll =>.Microsoft Windows®
O108 - CMH6: TeraCopy [64Bits] - {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} . (...) -- C:\Program Files\TeraCopy\TeraCopyExt.dll =>.Code Sector®
O108 - CMH6: UnLockerMenu [64Bits] - {410BF280-86EF-4E0F-8279-EC5848546AD3} . (.IObit - IObitUnlockerExtension.) -- C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll =>.IObit Information Technology®
O108 - CMH6: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH6: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.)
O108 - CMH7: Advanced SystemCare [64Bits] - {2803063F-4B8D-4dc6-8874-D1802487FE2D} . (.IObit - ASCExtMenu Module.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll =>.IObit Information Technology®
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL de Extensão do Shell do Armazenamento A.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O108 - CMH7: ESET Smart Security - Context Menu Shell Extension [64Bits] - {B089FE88-FB52-11D3-BDF1-0050DA34150D} . (.ESET - ESET Shell Extension.) -- C:\Program Files\ESET\ESET Security\shellExt.dll =>.ESET, spol. s r.o.®
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH7: TeraCopy [64Bits] - {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} . (...) -- C:\Program Files\TeraCopy\TeraCopyExt.dll =>.Code Sector®

---\ Image File Execution Options (17) - 1s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Módulo de Instalação de Driver.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Utilitário de Instalação Autônoma do IE 7.0.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Console de Gerenciamento Microsoft.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Host de Aplicativo HTML da Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Host do Windows Presentation Foundation.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Aplicativo de subsistema de spooler.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processo de Host para Serviços do Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processo de Host para Serviços do Windows.) [MitigationAuditOptions\\17660905521152] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\ Lista dos drivers do sistema (71) - 15s
O58 - SDL:2017/09/29 10:41:02 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107416] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135512] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83352] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [258592] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27032] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131992] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (. - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Broadcom Corporation
O58 - SDL:2017/09/29 10:40:59 A . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless dr.) -- C:\WINDOWS\System32\drivers\BCMWL63a.SYS [7585280] =>.Broadcom Corporation
O58 - SDL:2013/02/08 04:02:10 A . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless dr.) -- C:\WINDOWS\System32\drivers\BCMWL664.SYS [5443648] =>.Broadcom Corporation®
O58 - SDL:2017/09/29 10:41:01 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [533912] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [141208] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [357272] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T5/T6 Chip.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [1723288] =>.Microsoft Windows®
O58 - SDL:2015/06/24 10:39:12 A . (.Cypress Semiconductor, Inc. - Trackpad Driver.) -- C:\WINDOWS\System32\drivers\cykbfltr.sys [19968] =>.Cypress Semiconductor, Inc.
O58 - SDL:2012/12/13 12:41:10 A . (. - Explore Systems Virtual Audio Device.) -- C:\WINDOWS\System32\drivers\dfx11_1x64.sys [28008] =>.Power Technology®
O58 - SDL:2018/03/22 10:23:14 A . (.ESET - Amon monitor.) -- C:\WINDOWS\System32\drivers\eamonm.sys [133352] =>.ESET, spol. s r.o.®
O58 - SDL:2017/05/04 12:18:04 A . (.ESET - Devmon monitor.) -- C:\WINDOWS\System32\drivers\edevmon.sys [107344] =>.ESET, spol. s r.o.®
O58 - SDL:2018/02/19 09:19:04 A . (.ESET - ESET ELAM driver.) -- C:\WINDOWS\System32\drivers\eelam.sys [15872] {33000001DD353F6BD31990E1520000000001DD} =>.ESET
O58 - SDL:2018/03/22 10:23:14 A . (.ESET - ESET Helper driver.) -- C:\WINDOWS\System32\drivers\ehdrv.sys [180088] =>.ESET, spol. s r.o.®
O58 - SDL:2017/05/04 12:18:04 A . (.ESET - ESET OPP Keyboard Filter.) -- C:\WINDOWS\System32\drivers\ekbdflt.sys [50752] =>.ESET, spol. s r.o.®
O58 - SDL:2017/05/04 12:18:04 A . (.ESET - ESET Personal Firewall driver.) -- C:\WINDOWS\System32\drivers\epfw.sys [78192] =>.ESET, spol. s r.o.®
O58 - SDL:2018/03/22 10:23:14 A . (.ESET - ESET Personal Firewall driver.) -- C:\WINDOWS\System32\drivers\epfwwfp.sys [102160] =>.ESET, spol. s r.o.®
O58 - SDL:2017/09/29 10:41:01 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419032] =>.Microsoft Windows®
O58 - SDL:2013/02/19 05:59:38 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [57848] =>.Intel Corporation - Intel® Management Engine Firmware®
O58 - SDL:2017/09/29 10:41:02 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [63520] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:40:59 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [36864] =>.Intel(R) Corporation
O58 - SDL:2017/09/29 10:40:59 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [91648] =>.Intel(R) Corporation
O58 - SDL:2017/09/29 10:40:59 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [79360] =>.Intel Corporation
O58 - SDL:2017/09/29 10:40:59 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [88576] =>.Intel Corporation
O58 - SDL:2017/09/29 10:40:59 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [171520] =>.Intel Corporation
O58 - SDL:2017/09/29 10:40:59 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [174592] =>.Intel Corporation
O58 - SDL:2017/09/29 10:41:01 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2017/09/29 10:40:59 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2015/05/29 11:05:32 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [646408] =>.Intel Corporation - Rapid Storage Technology®
O58 - SDL:2017/09/29 10:41:03 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [674200] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:03 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412056] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [526232] =>.Microsoft Windows®
O58 - SDL:2014/11/28 21:37:06 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [180648] =>.Tonec Inc.®
O58 - SDL:2012/11/26 17:26:12 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [12311776] =>.Intel Corporation
O58 - SDL:2010/02/10 16:02:00 A . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\WINDOWS\System32\drivers\Impcd.sys [158720] =>.Intel Corporation
O58 - SDL:2017/09/29 10:41:02 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108064] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [123800] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [103320] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82840] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59800] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [63520] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575896] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [842648] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63896] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [108952] =>.Microsoft Windows®
O58 - SDL:2013/02/28 22:49:12 A . (.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\WINDOWS\System32\drivers\npf.sys [36600] =>.Riverbed Technology, Inc.®
O58 - SDL:2017/09/29 10:41:02 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150424] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166296] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58776] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
O58 - SDL:2018/01/25 15:32:38 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [1026896] =>.Realtek Semiconductor Corp.®
O58 - SDL:2017/09/29 10:41:14 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\WINDOWS\System32\drivers\rteth.sys [59904] =>.Realtek
O58 - SDL:2018/02/27 07:58:51 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\WINDOWS\System32\drivers\RtsUer.sys [424384] =>.Realtek Semiconductor Corp.®
O58 - SDL:2017/09/29 10:41:02 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44952] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81816] =>.Microsoft Windows®
O58 - SDL:2017/05/18 22:17:28 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [131984] =>.Samsung Electronics Co., Ltd.®
O58 - SDL:2017/09/29 10:41:02 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31128] =>.Microsoft Windows®
O58 - SDL:2010/08/04 19:27:06 A . (.IDT, Inc. - IDT PC Audio.) -- C:\WINDOWS\System32\drivers\stwrt64.sys [515584] =>.IDT, Inc.
O58 - SDL:2017/01/17 15:44:26 N . (.STMicroelectronics - STM Accelerometer Device Driver.) -- C:\WINDOWS\System32\drivers\ST_Accel.sys [149128] =>.STMICROELECTRONICS S.R.L.®
O58 - SDL:2011/04/22 11:24:38 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\WINDOWS\System32\drivers\SynTP.sys [1438768] =>.Synaptics Incorporated®
O58 - SDL:2016/04/21 06:10:04 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2017/09/29 10:41:02 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166808] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305560] =>.Microsoft Windows®
O58 - SDL:2018/02/26 18:33:16 A . (.Western Digital Technologies, Inc. - Western Digital SCSI Architecture Model (SA.) -- C:\WINDOWS\System32\drivers\wdcsam64.sys [35584] =>.WDKTestCert wdclab,130885612892544312®
O58 - SDL:2017/09/29 10:41:02 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [32152] =>.Microsoft Windows®
O58 - SDL:2017/09/29 10:41:02 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®

---\ Últimos ficheiros alterados ou criados (Utilizador) (12) - 17s
O61 - LFC: 2018/04/03 15:03:43 A . (.A.E.T. Europe B.V..) -- C:\Users\Pedro\Documents\TI\Ativação - 2018\Softwares\CERTISIGN\x64\1 - SafeSign_3.0.112_64bits.exe [10365312] {536FACE05A9369F23CE9A6ECD340738B}
O61 - LFC: 2018/04/03 15:04:16 A . (..) -- C:\Users\Pedro\Documents\TI\Ativação - 2018\Softwares\CERTISIGN\x64\2 - AWP_Manager_5.1.8_64_bits.exe [17903616]
O61 - LFC: 2018/04/03 15:09:21 A . (.A.E.T. Europe B.V..) -- C:\Users\Pedro\Documents\TI\Ativação - 2018\Softwares\CERTISIGN\x86\1 - SafeSign_3.0.112_32bits.exe [7014184]
O61 - LFC: 2018/04/03 15:09:45 A . (..) -- C:\Users\Pedro\Documents\TI\Ativação - 2018\Softwares\CERTISIGN\x86\2 - AWP_Manager_5.1.8_32_bits.exe [9551872]
O61 - LFC: 2018/04/03 15:03:43 A . (.A.E.T. Europe B.V..) -- C:\Users\Pedro\Documents\TI\Softwares\CERTISIGN\x64\1 - SafeSign_3.0.112_64bits.exe [10365312] {536FACE05A9369F23CE9A6ECD340738B}
O61 - LFC: 2018/04/03 15:04:16 A . (..) -- C:\Users\Pedro\Documents\TI\Softwares\CERTISIGN\x64\2 - AWP_Manager_5.1.8_64_bits.exe [17903616]
O61 - LFC: 2018/04/03 15:09:21 A . (.A.E.T. Europe B.V..) -- C:\Users\Pedro\Documents\TI\Softwares\CERTISIGN\x86\1 - SafeSign_3.0.112_32bits.exe [7014184]
O61 - LFC: 2018/04/03 15:09:45 A . (..) -- C:\Users\Pedro\Documents\TI\Softwares\CERTISIGN\x86\2 - AWP_Manager_5.1.8_32_bits.exe [9551872]
O61 - LFC: 2018/04/03 15:03:43 N . (.A.E.T. Europe B.V..) -- C:\Users\Pedro\vBox\Operacional - Vinhas Advogados\Ativação - 2018\Softwares\CERTISIGN\x64\1 - SafeSign_3.0.112_64bits.exe [10365312] {536FACE05A9369F23CE9A6ECD340738B}
O61 - LFC: 2018/04/03 15:04:16 N . (..) -- C:\Users\Pedro\vBox\Operacional - Vinhas Advogados\Ativação - 2018\Softwares\CERTISIGN\x64\2 - AWP_Manager_5.1.8_64_bits.exe [17903616]
O61 - LFC: 2018/04/03 15:09:21 N . (.A.E.T. Europe B.V..) -- C:\Users\Pedro\vBox\Operacional - Vinhas Advogados\Ativação - 2018\Softwares\CERTISIGN\x86\1 - SafeSign_3.0.112_32bits.exe [7014184]
O61 - LFC: 2018/04/03 15:09:45 N . (..) -- C:\Users\Pedro\vBox\Operacional - Vinhas Advogados\Ativação - 2018\Softwares\CERTISIGN\x86\2 - AWP_Manager_5.1.8_32_bits.exe [9551872]

---\ Associações Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- '%1' %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe '%1' %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- '%1' /S =>.Default.Value

---\ Menu de inicialização Internet (12) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\ Pesquisa de infeção nos navegadores da Internet (2) - 4s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\ Listagem dos serviços iniciados pelo Svchost (49) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\WINDOWS\System32\certprop.dll [188928] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\Windows\System32\certprop.dll [188928] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\Windows\System32\srvsvc.dll [270848] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [1275904] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\IKEEXT.DLL [984064] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\Windows\System32\iphlpsvc.dll [820224] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\Windows\System32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\Windows\System32\appinfo.dll [144896] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\Windows\System32\iscsiexe.dll [150528] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\Windows\System32\eapsvc.dll [109056] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\Windows\System32\schedsvc.dll [880640] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [220160] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [407040] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho.) -- C:\Windows\System32\SessEnv.dll [387584] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\Windows\System32\wercplsupport.dll [108544] =>.Microsoft Corporation
O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [254976] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [194560] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1272320] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Serviço de Autenticação Natural.) -- C:\Windows\System32\NaturalAuth.dll [795136] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Agente de Token.) -- C:\Windows\System32\TokenBroker.dll [1228800] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Serviço de Geolocalização.) -- C:\Windows\System32\lfsvc.dll [46080] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [1107968] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Monitor de infravermelho.) -- C:\Windows\System32\irmon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acess.) -- C:\Windows\System32\rasauto.dll [104960] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\Windows\System32\rasmans.dll [930816] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [491520] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) -- C:\Windows\System32\Sens.dll [73216] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\Windows\System32\ipnathlp.dll [601088] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft® Windows.) -- C:\Windows\System32\tapisrv.dll [307200] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2784256] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) -- C:\Windows\System32\qmgr.dll [1345536] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [613376] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL do Serviço de Gerenciamento do Windows.) -- C:\Windows\System32\Windows.Internal.Management.dll [702464] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Configurações da Nova Versão.) -- C:\Windows\System32\flightsettings.dll [779264] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Serviço do Sistema de Notificação por Push.) -- C:\Windows\System32\WpnService.dll [284672] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1143808] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Atualizar Sessão do Orchestrator Core.) -- C:\Windows\System32\usocore.dll [1296896] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [951808] =>.Microsoft Corporation
O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [1313792] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\Windows\System32\themeservice.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [387072] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\Windows\System32\DeviceSetupManager.dll [238080] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Serviço de Configuração de Rede.) -- C:\Windows\System32\NetSetupSvc.dll [308224] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede.) -- C:\Windows\System32\NcaSvc.dll [170496] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [2222592] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação do software.) -- C:\Windows\System32\appmgmts.dll [196096] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\Windows\System32\browser.dll [132608] =>.Microsoft Corporation

---\ Lista das exceções do FireWall (FirewallRules) (15) - 3s
O87 - FAEL: '{8AC8104F-A6EB-4EAE-9EC0-4BA6B30E46F2}' [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: '{CC903CD1-8CAA-48CB-9DA8-68BF54897746}' [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: '{522E5E6E-789B-42F0-AA56-32A802B8B0E6}' [In-None-P6-TRUE] .(.GlavSoft LLC. - TightVNC Server.) -- C:\Program Files\TightVNC\tvnserver.exe =>.GlavSoft LLC.®
O87 - FAEL: '{F9210560-7174-48E6-B984-513A4003C1C1}' [In-None-P6-TRUE] .(.Flash-Integro LLC - VSDC Video Editor Crack UZ1.) -- C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe =>.Flash-Integro LLC
O87 - FAEL: '{16B83FB5-E9FA-4338-AC95-0273F5D06F1E}' [In-None-P17-TRUE] .(.Flash-Integro LLC - VSDC Video Editor Crack UZ1.) -- C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe =>.Flash-Integro LLC
O87 - FAEL: '{12C9F7B2-8835-490C-827C-9EABF7F1C11E}' [In-None-P6-TRUE] .(.Flash-Integro LLC - VSDC Activation.) -- C:\Program Files\FlashIntegro\VideoEditor\Activation.exe =>.Vector Ltd.®
O87 - FAEL: '{9470D43C-6173-4838-8BBA-F83F6378B8AE}' [In-None-P17-TRUE] .(.Flash-Integro LLC - VSDC Activation.) -- C:\Program Files\FlashIntegro\VideoEditor\Activation.exe =>.Vector Ltd.®
O87 - FAEL: '{A3301E3C-FF23-4A7A-8D20-BC1A8F382B98}' [In-None-P6-TRUE] .(.Flash-Integro LLC - VSDC Updater.) -- C:\Program Files\FlashIntegro\VideoEditor\Updater.exe =>.Vector Ltd.®
O87 - FAEL: '{F0593124-7F7C-483E-B882-2371988BD9DF}' [In-None-P17-TRUE] .(.Flash-Integro LLC - VSDC Updater.) -- C:\Program Files\FlashIntegro\VideoEditor\Updater.exe =>.Vector Ltd.®
O87 - FAEL: '{D713890E-324A-4009-8D85-36B602E6F26B}' [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 13.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®
O87 - FAEL: '{D96D0605-B5DE-478E-B8B5-A1AE704DECC4}' [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 13.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®
O87 - FAEL: '{5F2DB391-76FD-4487-AAE9-CD6BA1E64D44}' [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 13.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®
O87 - FAEL: '{4DA72A1B-1404-4014-A1B1-1124C5F425CA}' [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 13.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®
O87 - FAEL: '{F2B126E1-A33E-4338-9AB8-15632E84C9A0}' [In-None-P17-TRUE] .(.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O87 - FAEL: '{2B737101-ED68-4FC4-81CA-FF61788D728D}' [In-None-P17-TRUE] .(.3CX Ltd - 3CX VoIP Phone.) -- C:\Program Files (x86)\3CXPhone\3CXPhone.exe

---\ Pesquisa dos pacotes WindowsInstaller (19) - 12s
[MD5.232F86E422C9ACAB293E2E350CAE709B] [WIS][2011/06/06 17:59:21] (.Adobe Systems Incorporated - ADOBER~1.0
Adobe Reader X (10.0.1).) -- C:\WINDOWS\Installer\11fa8b.msi [2328064] =>.Adobe Systems Incorporated
[MD5.E0F2263D541949922BDF6B285C4FF510] [WIS][2015/06/16 16:06:48] (.TechSmith Corporation - Snagit 12.4.0.2992.) -- C:\WINDOWS\Installer\11fa91.msi [91419648] =>.TechSmith Corporation
[MD5.E4EECA96E08781FA6F948A70EDE0C458] [WIS][2018/03/12 10:04:56] (.Oracle Corporation - Java SE Runtime Environment 8 Update 144.) -- C:\WINDOWS\Installer\14158e3b.msi [56287232] =>.Oracle Corporation
[MD5.EB81C40818A7B63F68D1735D48810953] [WIS][2018/03/12 10:08:02] (.Oracle Corporation - Java SE Runtime Environment 8 Update 144.) -- C:\WINDOWS\Installer\14158e45.msi [62558208] =>.Oracle Corporation
[MD5.C9D0B6960243A17E86E117E95681CFDC] [WIS][2018/03/12 11:17:14] (.Oracle Corporation - Java(TM) SE Runtime Environment 9.0.4.) -- C:\WINDOWS\Installer\145a8d23.msi [98238464] =>.Oracle Corporation
[MD5.109C6A53BC9D0F221606840D1DA86F0F] [WIS][2017/11/14 13:17:47] (.Adobe Systems, Inc - Adobe Shockwave Player 12.3.) -- C:\WINDOWS\Installer\145a8e94.msi [24259584] =>.Adobe Systems, Inc
[MD5.CEEC4DBD300086C8F052BDC51D287CA5] [WIS][2018/04/02 16:07:00] (.3CX - 3CXPhone.) -- C:\WINDOWS\Installer\147183ca.msi [13994496] =>.3CX
[MD5.25B47EFBE9DCEF40BB9760B6B7846B99] [WIS][2017/03/31 03:36:54] (.Adobe Systems, Inc - swMSM.) -- C:\WINDOWS\Installer\1553f9.msi [2118144] =>.Adobe Systems, Inc
[MD5.758633B2268060FF2393156652F9E2FB] [WIS][2013/07/01 20:30:30] (.Famatech - Advanced IP Scanner.) -- C:\WINDOWS\Installer\1bb4d8.msi [5947392] =>.Famatech
[MD5.60D23DFC5B711DB03C49D7A5E5D47143] [WIS][2018/02/07 09:52:36] (..) -- C:\WINDOWS\Installer\346a39.msi [1566208]
[MD5.0239D9D6324291B3433EF0E5021644C7] [WIS][2018/02/07 09:55:27] (.Oberthur Technologies - AWP 5.1.8 (64-bit) 5.1.8.825.) -- C:\WINDOWS\Installer\346a3c.msi [17829888]
[MD5.D1038CE4B919E199E81C7C9CCBC2B752] [WIS][2018/03/29 10:04:41] (.Google, Inc. - Backup and Sync from Google.) -- C:\WINDOWS\Installer\3ebcd08.msi [57098240] =>.Google, Inc.
[MD5.4EC5143C1460DB67AD592760B4CE8817] [WIS][2018/03/01 12:49:15] (.Banco Itaú - Aplicativo Navegador Seguro Itaú.) -- C:\WINDOWS\Installer\3f0ef65.msi [70619136] =>.Banco Itaú
[MD5.2FC1E7A12F792B6627C4FB92CDCCD4CD] [WIS][2007/10/01 10:38:00] (.Nero AG.) -- C:\WINDOWS\Installer\4132b1.msi [1404416] =>.Nero AG
[MD5.98C8F8C2A68FACC2C78503F5BD452EEB] [WIS][2017/03/03 09:47:36] (.EMC Corporation - RSA SecurID Token.) -- C:\WINDOWS\Installer\5059f4.msi [27254784] =>.EMC Corporation
[MD5.349575DC788C24C6C726356D55D3CBAA] [WIS][2018/02/09 12:39:35] (.GlavSoft LLC. - TightVNC.) -- C:\WINDOWS\Installer\5225137.msi [2367488] =>.GlavSoft LLC.
[MD5.695B4041D41D440931DDBB08D349A23B] [WIS][2018/01/21 15:47:42] (.ESET, spol. s r.o. - ESET Smart Security.) -- C:\WINDOWS\Installer\596c47.msi [120598528] =>.ESET, spol. s r.o.
[MD5.F0EE2E7F283866A2A0FEA9BE2D12A979] [WIS][2018/02/06 22:48:08] (.Google Inc. - Google Update Helper.) -- C:\WINDOWS\Installer\a6bee.msi [40960] =>.Google Inc.

---\ Scâner Aditional (37) - 4s
HKLM\SYSTEM\CurrentControlSet\Services\Service KMSELDI =>HackTool.KMSpico
C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
C:\Program Files\KMSpico\AutoPico.exe =>HackTool.KMSpico
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart =>HackTool.KMSpico
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =>.SUP.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =>.SUP.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =>.SUP.Orphan
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>HackTool.KMSpico
C:\Program Files\Hola =>PUP.Optional.HolaSearch
C:\Program Files\KMSpico =>HackTool.KMSpico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
C:\Users\Pedro\AppData\Roaming\Hola =>PUP.Optional.HolaSearch
C:\Users\Pedro\AppData\Roaming\PCProtect =>.SUP.PCProtect
C:\Users\Pedro\AppData\Local\AdvinstAnalytics =>.SUP.Various
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\000 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\002 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\005 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\010 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\011 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\012 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\013 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\014 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\015 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\016 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\017 =>.SUP.Temporary.Chrome
C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\File System\018 =>.SUP.Temporary.Chrome

---\ Resumo dos elementos encontrados na sua estação de trabalho (8) - 0s
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico
https://nicolascoolman.eu/2017/02/02/superfluous-cloudfrontnet/ =>.SUP.CloudfrontNet
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>BitTorrent (P2P)
https://www.nicolascoolman.com/fr/hijacker-holasearch/ =>PUP.Optional.HolaSearch
https://nicolascoolman.eu/2017/10/30/sup-pcprotect/ =>.SUP.PCProtect
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Various
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome

~ Unselected Options: O82,
~ End of the scan, 8316 items in 02mn50s (1593)(0)

[00AEBC84B4706FFB885797E0EB5CEC7C93] [02/03/2018] (.Vector Ltd..) - C:\Program Files\FlashIntegro\unins000.exe
[00AEBC84B4706FFB885797E0EB5CEC7C93] [17/01/2018] (.Vector Ltd..) - C:\Program Files\FlashIntegro\VideoEditor\Activation.exe
[00AEBC84B4706FFB885797E0EB5CEC7C93] [17/01/2018] (.Vector Ltd..) - C:\Program Files\FlashIntegro\VideoEditor\Updater.exe
[0290965E913340CDA6634CEF31F7FD07] [06/06/2011] (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe
[0290965E913340CDA6634CEF31F7FD07] [06/06/2011] (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[0290965E913340CDA6634CEF31F7FD07] [06/06/2011] (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
[0320BE3EB866526927F999B97B04346E] [25/01/2018] (.Realtek Semiconductor Corp..) - C:\WINDOWS\System32\drivers\rt640x64.sys
[0320BE3EB866526927F999B97B04346E] [27/02/2018] (.Realtek Semiconductor Corp..) - C:\WINDOWS\System32\drivers\RtsUer.sys
[034F328F3EFF4FB98F5343811788F78A] [05/12/2014] (.Tonec Inc..) - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
[034F328F3EFF4FB98F5343811788F78A] [07/11/2013] (.Tonec Inc..) - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
[034F328F3EFF4FB98F5343811788F78A] [21/04/2014] (.Tonec Inc..) - C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll
[034F328F3EFF4FB98F5343811788F78A] [25/08/2014] (.Tonec Inc..) - C:\Program Files (x86)\Internet Download Manager\Uninstall.exe
[034F328F3EFF4FB98F5343811788F78A] [28/11/2014] (.Tonec Inc..) - C:\WINDOWS\System32\drivers\idmwfp.sys
[03E49B29AE75DF4C50DC1662670776B9] [26/10/2017] (.OpenVPN Technologies, Inc..) - C:\Program Files\OpenVPN\bin\openvpn-gui.exe
[03E49B29AE75DF4C50DC1662670776B9] [26/10/2017] (.OpenVPN Technologies, Inc..) - C:\Program Files\OpenVPN\bin\openvpnserv.exe
[0511EAF8579E2662BE622DE5AE0CD408] [06/11/2014] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
[0511EAF8579E2662BE622DE5AE0CD408] [06/11/2014] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
[055F937A9DF73DFD90BA9889E4C50A11] [18/03/2018] (.Notepad++.) - C:\Program Files (x86)\Notepad++\NppShell_06.dll
[0664CADB13C394F908C7E2BDF7114CC6] [09/01/2018] (.eFolder, Inc..) - C:\Program Files (x86)\vBox\bin\agent_gui.exe
[0664CADB13C394F908C7E2BDF7114CC6] [09/01/2018] (.eFolder, Inc..) - C:\Program Files (x86)\vBox\bin\agent_service.exe
[0664CADB13C394F908C7E2BDF7114CC6] [09/01/2018] (.eFolder, Inc..) - C:\Program Files (x86)\vBox\bin\x64\anchoroverlay.dll
[06F04788031055D31DEFFEFCD026D6C5] [02/04/2018] (.Adobe Systems Incorporated.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\User Data\PepperFlash\29.0.0.140\pepflashplayer.dll
[06F04788031055D31DEFFEFCD026D6C5] [06/04/2018] (.Adobe Systems Incorporated.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\User Data\PepperFlash\29.0.0.147\pepflashplayer.dll
[06F04788031055D31DEFFEFCD026D6C5] [13/03/2018] (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
[06F04788031055D31DEFFEFCD026D6C5] [13/03/2018] (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_pepper.exe
[06F04788031055D31DEFFEFCD026D6C5] [13/03/2018] (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe
[0788260F8541539D97F49DDAA837B166] [06/02/2018] (.TechSmith Corporation.) - C:\ProgramData\Package Cache\{ae5218bf-cfcc-4099-818d-7e16ce0d97df}\Bootstrapper.exe
[0788260F8541539D97F49DDAA837B166] [16/06/2015] (.TechSmith Corporation.) - C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll
[0788260F8541539D97F49DDAA837B166] [16/06/2015] (.TechSmith Corporation.) - C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
[0788260F8541539D97F49DDAA837B166] [16/06/2015] (.TechSmith Corporation.) - C:\Program Files (x86)\TechSmith\Snagit 12\snagiteditor.exe
[0788260F8541539D97F49DDAA837B166] [16/06/2015] (.TechSmith Corporation.) - C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
[0A16AE9F0A11D38047CDDA823769F520] [23/02/2018] (.Wireshark Foundation, Inc..) - C:\Program Files (x86)\Wireshark\uninstall.exe
[0A16AE9F0A11D38047CDDA823769F520] [23/02/2018] (.Wireshark Foundation, Inc..) - C:\Program Files (x86)\Wireshark\Wireshark.exe
[0C5396DCB2949C70FAC48AB08A07338E] [24/01/2018] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
[0C5396DCB2949C70FAC48AB08A07338E] [24/01/2018] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
[0C5396DCB2949C70FAC48AB08A07338E] [24/01/2018] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Thunderbird\uninstall\helper.exe
[0CF35369A9710762C36F6805FC9E45D6] [08/02/2018] (.BitTorrent Inc.) - C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe
[0E4C1A84EE436C73F30978E7D4C34C0B] [18/05/2017] (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\drivers\ssudbus.sys
[10EB1CAFF23CFA81BF0649EFD5024332] [05/05/2017] (.Code Sector.) - C:\Program Files\TeraCopy\TeraCopyService.exe
[10EB1CAFF23CFA81BF0649EFD5024332] [06/02/2018] (.Code Sector.) - C:\Program Files\TeraCopy\unins000.exe
[10EB1CAFF23CFA81BF0649EFD5024332] [07/12/2016] (.Code Sector.) - C:\Program Files\TeraCopy\TeraCopyExt.dll
[1121DCD4E0587301475C5B5C985A80B20FBB] [07/02/2018] (.LAZYSOFT TECHNIQUE LTD.) - C:\Program Files (x86)\Lazesoft Recovery Suite\unins000.exe
[119B09803E11C7BE685861F72F128819] [07/03/2018] (.crystalidea.com.) - C:\Program Files (x86)\AnyToISO\unins000.exe
[11CADAF29DA4C3CB113BF1877B120103] [15/07/2015] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll
[12F0277E0F233B39F9419B06E8CDE352] [12/03/2018] (.Oracle America, Inc..) - C:\Program Files\Java\jre-9.0.4\bin\jp2ssv.dll
[1402AEEF0D31BE743E73F6A7A960C4F4] [28/02/2013] (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe
[1402AEEF0D31BE743E73F6A7A960C4F4] [28/02/2013] (.Riverbed Technology, Inc..) - C:\WINDOWS\System32\drivers\npf.sys
[14F8FDD167F92402B1570B5DC495C815] [05/03/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleCrashHandler.exe
[14F8FDD167F92402B1570B5DC495C815] [05/03/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
[14F8FDD167F92402B1570B5DC495C815] [05/03/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe
[14F8FDD167F92402B1570B5DC495C815] [06/02/2018] (.Google Inc.) - C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
[14F8FDD167F92402B1570B5DC495C815] [06/02/2018] (.Google Inc.) - C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
[14F8FDD167F92402B1570B5DC495C815] [28/06/2017] (.Google Inc.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[158B53F6910CDB984F848EE6B39269A1] [26/02/2018] (.WDKTestCert wdclab,130885612892544312.) - C:\WINDOWS\System32\drivers\wdcsam64.sys
[1701CEEB000100009028] [19/02/2013] (.Intel Corporation - Intel® Management Engine Firmware.) - C:\WINDOWS\System32\drivers\HECIx64.sys
[1953BFF7773C9644F9AA285A2E2A49AF] [12/11/2014] (.Power Technology.) - C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe
[1953BFF7773C9644F9AA285A2E2A49AF] [12/11/2014] (.Power Technology.) - C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe
[1DE10DED541D51E73BC486F492498836] [04/05/2017] (.ESET, spol. s r.o..) - C:\WINDOWS\System32\drivers\edevmon.sys
[1DE10DED541D51E73BC486F492498836] [04/05/2017] (.ESET, spol. s r.o..) - C:\WINDOWS\System32\drivers\ekbdflt.sys
[1DE10DED541D51E73BC486F492498836] [04/05/2017] (.ESET, spol. s r.o..) - C:\WINDOWS\System32\drivers\epfw.sys
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\Program Files\ESET\ESET Security\callmsi.exe
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\Program Files\ESET\ESET Security\ecmds.exe
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\Program Files\ESET\ESET Security\egui.exe
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\Program Files\ESET\ESET Security\ekrn.exe
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\Program Files\ESET\ESET Security\shellExt.dll
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\WINDOWS\System32\drivers\eamonm.sys
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\WINDOWS\System32\drivers\ehdrv.sys
[1DE10DED541D51E73BC486F492498836] [22/03/2018] (.ESET, spol. s r.o..) - C:\WINDOWS\System32\drivers\epfwwfp.sys
[20A20DFCE424E6BBCC162A5FCC0972EE] [09/03/2018] (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer.exe
[20A20DFCE424E6BBCC162A5FCC0972EE] [09/03/2018] (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
[20A20DFCE424E6BBCC162A5FCC0972EE] [09/03/2018] (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\uninstall.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\chrome.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\chrome_child.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\chrome_elf.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\chrome_watcher.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\eventlog_provider.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\Installer\setup.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\libegl.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\libglesv2.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\notification_helper.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\swiftshader\libegl.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\swiftshader\libglesv2.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3389.0\WidevineCdm\_platform_specific\win_x64\widevinecdm.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [05/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\chrome.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\chrome.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\chrome_child.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\chrome_elf.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\chrome_watcher.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\eventlog_provider.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\Installer\setup.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\libegl.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\libglesv2.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\notification_helper.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\swiftshader\libegl.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\swiftshader\libglesv2.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\67.0.3390.0\WidevineCdm\_platform_specific\win_x64\widevinecdm.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Chrome SxS\Application\new_chrome.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [06/04/2018] (.Google Inc.) - C:\Users\Pedro\AppData\Local\Google\Update\Download\{4EA16AC7-FD5A-47C3-875B-DBF4A2008C20}\67.0.3390.0\67.0.3390.0_67.0.3389.0_chrome_updater.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [15/03/2018] (.Google Inc.) - C:\Program Files\Google\Drive\contextmenu64.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [15/03/2018] (.Google Inc.) - C:\Program Files\Google\Drive\googledrivesync.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [15/03/2018] (.Google Inc.) - C:\Program Files\Google\Drive\googledrivesync64.dll
[2A9C21ACAAA63A3C58A7B9322BEE948D] [20/03/2018] (.Google Inc.) - C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\chrmstp.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [20/03/2018] (.Google Inc.) - C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\setup.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [20/03/2018] (.Google Inc.) - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[2A9C21ACAAA63A3C58A7B9322BEE948D] [28/06/2017] (.Google Inc.) - C:\Program Files (x86)\GUM1669.tmp\GoogleUpdateSetup.exe
[2DD0195E4C2A2BB2DD729803591178E7] [06/07/2017] (.OBERTHUR TECHNOLOGIES.) - C:\Program Files (x86)\Oberthur Technologies\AWP\IdentityManager.exe
[2DD0195E4C2A2BB2DD729803591178E7] [06/07/2017] (.OBERTHUR TECHNOLOGIES.) - C:\Program Files\Oberthur Technologies\AWP\OTCertSynchronizer.exe
[2E8573FEC17028570C352D7AE5247517] [13/12/2012] (.Power Technology.) - C:\WINDOWS\System32\drivers\dfx11_1x64.sys
[2EF2BE0C29BD08B957172FED0BE6A036] [19/07/2013] (.GlavSoft LLC..) - C:\Program Files\TightVNC\tvnserver.exe
[2FEE515AD7951C4A1D99C16E190BFEA3] [01/07/2013] (.Famatech Corp..) - C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe
[330000B31EB304F8BF60CF07D900020000B31E] [29/09/2017] (.Intel Corporation - Client Components Group.) - C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
[330000C4FE532CA47D2C2EF2F000030000C4FE] [29/05/2015] (.Intel Corporation - Rapid Storage Technology.) - C:\WINDOWS\System32\drivers\iaStorA.sys
[3C20348318029EC708BB1602D55E5B06] [05/11/2009] (.Acro Software Inc..) - C:\Program Files (x86)\Acro Software\CutePDF Writer\Setup64.exe
[40DF9F2D65D1C332995EC625226A8C2B] [01/03/2010] (.Softland.) - C:\Program Files\Softland\doPDF 7\dopdf.exe
[454A6CD2E1E63CA9D542DFDAB518FED9] [06/02/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\IObit Unlocker\unins000.exe
[454A6CD2E1E63CA9D542DFDAB518FED9] [08/02/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\unins000.exe
[454A6CD2E1E63CA9D542DFDAB518FED9] [15/01/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
[454A6CD2E1E63CA9D542DFDAB518FED9] [26/09/2017] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll
[50D95B1D70342FF9422CC45AD81ED7AC] [22/07/2017] (.Nsasoft US.) - C:\Program Files (x86)\Nsasoft\DhcpExplorer\DhcpExplorer.exe
[529E3F9FCF7D58D520D607AB74395002] [11/08/2017] (.win.rar GmbH.) - C:\Program Files\WinRAR\Ace32Loader.exe
[529E3F9FCF7D58D520D607AB74395002] [11/08/2017] (.win.rar GmbH.) - C:\Program Files\WinRAR\uninstall.exe
[529E3F9FCF7D58D520D607AB74395002] [16/06/2017] (.win.rar GmbH.) - C:\Program Files\WinRAR\RarExt.dll
[536FACE05A9369F23CE9A6ECD340738B] [03/04/2018] (.A.E.T. Europe B.V..) - C:\Users\Pedro\Documents\TI\Ativação - 2018\Softwares\CERTISIGN\x64\1 - SafeSign_3.0.112_64bits.exe
[536FACE05A9369F23CE9A6ECD340738B] [03/04/2018] (.A.E.T. Europe B.V..) - C:\Users\Pedro\Documents\TI\Softwares\CERTISIGN\x64\1 - SafeSign_3.0.112_64bits.exe
[536FACE05A9369F23CE9A6ECD340738B] [03/04/2018] (.A.E.T. Europe B.V..) - C:\Users\Pedro\vBox\Operacional - Vinhas Advogados\Ativação - 2018\Softwares\CERTISIGN\x64\1 - SafeSign_3.0.112_64bits.exe
[584613A643837F4A97FB085A48C09873] [25/02/2018] (.Hola Networks Ltd.) - C:\Program Files\Hola\app\7za.exe =>PUP.Optional.HolaSearch
[58F852EBA8EBE61A13F09288C4F1D562] [26/02/2018] (.Itau Unibanco S.A..) - C:\Users\Pedro\AppData\Local\Aplicativo Itau\itauaplicativo.exe
[5C207033D8165CF918205D4E1291D3FC] [09/01/2018] (.Open Source Developer, Dominik Reichl.) - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe
[5CD0502920C27EEAEC2A184D0452E53A] [07/02/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
[5CD0502920C27EEAEC2A184D0452E53A] [08/02/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\Suo10_SmartRAM.exe
[5CD0502920C27EEAEC2A184D0452E53A] [16/01/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
[5CD0502920C27EEAEC2A184D0452E53A] [30/01/2018] (.IObit Information Technology.) - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
[5DAA3A3A20C9CD75916087FD48E68CAC] [08/02/2013] (.Broadcom Corporation.) - C:\WINDOWS\System32\drivers\BCMWL664.SYS
[6170B7508957F9E3694298A421EA5A8A] [17/01/2017] (.STMICROELECTRONICS S.R.L..) - C:\WINDOWS\System32\drivers\ST_Accel.sys
[76385DE614BCBE5BAE4D49D9AE895CF7] [22/04/2011] (.Synaptics Incorporated.) - C:\Program Files\Synaptics\SynTP\DellTpad.exe
[76385DE614BCBE5BAE4D49D9AE895CF7] [22/04/2011] (.Synaptics Incorporated.) - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[76385DE614BCBE5BAE4D49D9AE895CF7] [22/04/2011] (.Synaptics Incorporated.) - C:\WINDOWS\System32\drivers\SynTP.sys

Publicité


Signaler le contenu de ce document

Publicité