~ Relatório do ZHPDiag v2015.6.4.54 - Nicolas Coolman (31-05-2015) ~ Iniciado por João (14-06-2015 19:49:52) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Endereço do Webforum : http://forum.nicolascoolman.fr ~ Tradução pelo utilizador ~ Estatuto da versão : Versão atualizada. ~ Lista Branca : Desativado pelo Utilizador ~ Elevação dos Privilégios : OK ~ Controle de Conta de Utilizador : Activate by user ---\\ Navegadores Internet MSIE: Internet Explorer v11.0.9600.17843 MFIE: Mozilla Firefox 38.0.5 GCIE: Google Chrome v43.0.2357.124 (Defaut) ---\\ Informações sobre os produtos Windows ~ Langage: Portugais Windows Server License Manager Script : OK Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601) ---\\ Softwares de proteçao do sistema Malwarebytes Anti-Malware versão 2.1.6.1022 Microsoft Security Client v4.8.0204.0 Spybot - Search & Destroy v2.4.40 Windows Defender W7 (Deactivate) ---\\ Softwares d'optimização do sistema CCleaner v4.10 ---\\ Softwares de partilha do PeerToPeer (P2P) ---\\ Monitoramento dos softwares Adobe Flash Player 17 NPAPI Adobe Reader XI ---\\ Informações sobre o sistema ~ Processor: x86 Family 15 Model 76 Stepping 2, AuthenticAMD ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2814 MB (57% free) System Restore: Activé (Enable) System drive C: has 19 GB (30%) free of 64 GB ---\\ Modo de conexão ao sistema ~ Computer Name: JOÃO-PC ~ User Name: João ~ All Users Names: João, HomeGroupUser$, Convidado, Administrador, ~ Unselected Option: None Logged in as Administrator ---\\ As variáveis de ambiente ~ System Unit : C:\ ~ %AppZHP% : C:\Users\João\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\João\AppData\Roaming\ ~ %Desktop% : C:\Users\João\Desktop\ ~ %Favorites% : C:\Users\João\Favorites\ ~ %LocalAppData% : C:\Users\João\AppData\Local\ ~ %StartMenu% : C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumeração das unidades dos discos C: Hard drive, Flash drive, Thumb drive (Free 19 Go of 64 Go) D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 48 Go) E: CD-ROM drive (Not Inserted) F: Floppy drive, Flash card reader, USB Key (Not Inserted) ---\\ Estado do Centro de Segurança do Windows [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 46 Scanned in 00mn 00s ---\\ Pesquisa particular de ficheiros genéricos [MD5.B0846DB5BDAB92131529A58E627FCEB7] - (.Microsoft Corporation - Explorador do Windows.) (.26-05-2013 - 20:51:48.) -- C:\Windows\Explorer.exe [2616320] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Aplicação de Arranque do Windows.) (.14-07-2009 - 01:14:45.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.E4EB138060BAE0DBAB1A3B71A3141FE7] - (.Microsoft Corporation - Extensões da Internet para Win32.) (.23-05-2015 - 02:20:35.) -- C:\Windows\System32\wininet.dll [1950720] [MD5.4F37B93C14AEE313BEC52A23AFB15C2E] - (.Microsoft Corporation - Aplicação de início de sessão do Windows.) (.16-07-2014 - 02:56:14.) -- C:\Windows\System32\Winlogon.exe [304640] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) (.20-11-2010 - 21:29:24.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.9876CB32F95AB3E7B56A86B8465399BE] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30-05-2014 - 06:25:58.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14-07-2009 - 01:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.13-07-2009 - 23:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BEF6CE8C3BFA3C849E9818712BF83D3E] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.26-05-2013 - 20:50:06.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.B44B9746261B23087690BF18821BA187] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.26-05-2013 - 20:57:40.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20-11-2010 - 21:29:03.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Controlador de porta i8042.) (.13-07-2009 - 23:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.13-07-2009 - 23:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.198320B27263A3B8199D17CAFA999646] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.26-05-2013 - 21:01:34.) -- C:\Windows\system32\Drivers\MRxSmb.sys [124416] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20-11-2010 - 21:29:08.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.90EE3C4BD199287D2630C5232F459367] - (.Microsoft Corporation - Controlador de Sistema de Ficheiros NT.) (.24-01-2014 - 02:00:31.) -- C:\Windows\system32\Drivers\ntfs.sys [1213376] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Controlador de porta paralela.) (.13-07-2009 - 23:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.13-07-2009 - 23:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.1F338AEE605991DDA422456EDDA359BF] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.26-05-2013 - 20:58:43.) -- C:\Windows\system32\Drivers\rdpdr.sys [133632] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.13-07-2009 - 23:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20-11-2010 - 21:29:07.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.4EDEF8AB59B089925CF9A6CFC74A4109] - (.Microsoft Corporation - Controlador de cópia sombra do volume.) (.26-05-2013 - 20:57:39.) -- C:\Windows\system32\Drivers\volsnap.sys [246104] ~ Generic Processes: Scanned in 00mn 00s ---\\ Estatuto dos ficheiros ocultos (Oculto/Total) ~ Mes images (My Pictures) : 1/3 ~ Mes musiques (My Musics) : 1/284 ~ Mes Favoris (My Favorites) : 1/3 ~ Mes Documents (My Documents) : 1/50 ~ Mon Bureau (My Desktop) : 1/2465 ~ Menu demarrer (Programs) : 1/34 ~ Hidden Files: Scanned in 00mn 05s ---\\ Processos lançados [MD5.DFFC976A9D802FAA434052A8EF6C34CB] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [815104] [PID.2540] [MD5.C493E204784A3076D1E33764C7CAFAC6] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [157480] [PID.2556] [MD5.F34E7705751BB413283434697BF8E55D] - (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe [357696] [PID.2572] [MD5.11C5C9A517E571DD4409FDB9C2AD20B6] - (...) -- C:\Users\João\AppData\Roaming\ACEStream\updater\ace_update.exe [22824] [PID.2600] [MD5.43DFDE6570A948A178000348950B3546] - (...) -- C:\Users\João\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe [22824] [PID.2608] [MD5.7B6CB5C60E549B746FA8DEEE82C5BB53] - (...) -- C:\Users\João\AppData\Roaming\ACEStream\engine\ace_engine.exe [23984] [PID.2616] [MD5.6B87742F27B087AF7FD4ADC2DB685DE0] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [49152] [PID.2676] [MD5.4C08FB7ACB28689B586D986D3F5826CF] - (.ATI Technologies Inc. - Catalyst Control Centre: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [49152] [PID.3412] [MD5.4547360EB0D90804B3AD080CE1D1D814] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [813896] [PID.3952] [MD5.12E2FC1F74265881402DE856D01EFFFE] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8214016] [PID.5544] ~ Processes Running: Scanned in 00mn 00s ---\\ Google Chrome, Arranque,Pesquisa,Extensões (G0,G1,G2) C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Preferences ---\\ Pasta de extensão do Google Chrome G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [__MSG_appName__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [__MSG_appName__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [__MSG_appName__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [__MSG_appName__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [__MSG_appName__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [__MSG_appName__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [__MSG_APP_NAME__] G2 - EXT: C:\Users\João\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [__MSG_appName__] ~ Google Lines Browser: 16 Scanned in 00mn 00s ---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (P2,M0,M1,M2,M3) P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-en-GB.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\priberam.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\sapo.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-ptpt.xml P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.40.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.40.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.40.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.3] - (.VideoLAN - VLC media player Web Plugin 2.1.3.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.11.) -- C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll P2 - FPN: [HKLM] [PDF Architect 2] - (.pdfforge GmbH - PDF Architect 2.) -- C:\Program Files\PDF Architect 2\np-previewer.dll P2 - FPN: [HKCU] [@acestream.net/acestreamplugin,version=3.0.12] - (.Innovative Digital Technologies - ACE Stream Plug-in Version 2.2.5.1-next, Copyright (c) 2012-2014 Innov.) -- C:\Users\João\AppData\Roaming\ACEStream\player\npace_plugin.dll ~ Firefox Browser: 22 Scanned in 00mn 00s ---\\ Internet Explorer, Arranque, Pesquisa, URLSearchHook( gancho de URL), Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Innovative Digital Technologies - ACE Stream Plug-in Version 2.2.5.1-next, Copyright (c) 2012-2014 Innov.) (No version) -- (.not file.) R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ IE Browser: 10 Scanned in 00mn 00s ---\\ Internet Explorer, Gestão do Proxy (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Análise das linhas F0, F1, F2, F3 - Ficheiros ini, Carregamento Automático de programas F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Redireção do ficheiro Hosts (01) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn 00s ---\\ Browser Helper Objects do navegador (02) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll ~ BHO: 4 Scanned in 00mn 00s ---\\ Outras conexões do utilizador (04) O4 - GS\QuickLaunch [João]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) -- C:\Users\João\AppData\Roaming\BitTorrent\BitTorrent.exe =>P2P.BitTorrent ~ Global Startup: 1 Scanned in 00mn 03s ---\\ Aplicações iniciadas por registo & pastas (04) O4 - HKLM\..\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd O4 - HKCU\..\Run: [AceUpdater] . (...) -- C:\Users\João\AppData\Roaming\ACEStream\updater\ace_update.exe O4 - HKCU\..\Run: [AceWebExtensionUpdater] . (...) -- C:\Users\João\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe O4 - HKCU\..\Run: [AceStream] . (...) -- C:\Users\João\AppData\Roaming\ACEStream\engine\ace_engine.exe O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd. or its subsidiaries - Garmin Express Tray.) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe =>.Garmin Corporation O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd. or its subsidiaries - Garmin Express Tray.) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe =>.Garmin Corporation O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Miniaplicações de Ambiente de Trabalho do W.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Miniaplicações de Ambiente de Trabalho do W.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-937454655-4104879931-1372932852-1001\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd O4 - HKUS\S-1-5-21-937454655-4104879931-1372932852-1001\..\Run: [AceUpdater] . (...) -- C:\Users\João\AppData\Roaming\ACEStream\updater\ace_update.exe O4 - HKUS\S-1-5-21-937454655-4104879931-1372932852-1001\..\Run: [AceWebExtensionUpdater] . (...) -- C:\Users\João\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe O4 - HKUS\S-1-5-21-937454655-4104879931-1372932852-1001\..\Run: [AceStream] . (...) -- C:\Users\João\AppData\Roaming\ACEStream\engine\ace_engine.exe ~ Application: Scanned in 00mn 00s ---\\ Icones das opções IE invisiveis no painel das configurações (05) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fornecedor de Correcções de Compatibilidade de Nomenclatura de Correio El.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fornecedor de Espaço de Nomes PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fornecedor de Espaço de Nomes PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços de Microsoft Windows Sockets 2.0.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll ~ Winsock: 7 Scanned in 00mn 00s ---\\ Alteração Dominio/Clientes DNS (017) O17 - HKLM\System\CCS\Services\Tcpip\..\{28AB56AE-A4DC-4493-89E4-B5268651C024}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{28AB56AE-A4DC-4493-89E4-B5268651C024}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{28AB56AE-A4DC-4493-89E4-B5268651C024}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocolo adicional (018) O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valor do Registo AppInit_DLLs e sub-chaves Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: SDWinLogon . (...) -- SDWinLogon.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Chave do Registo autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s ---\\ Lista dos serviços NT não Microsoft e não desativados (023) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: (Ati External Event Utility) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\Windows\System32\Ati2evxx.exe O23 - Service: Serviço de Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Serviço Google Update (gupdate) (gupdate) . (.Google Inc. - Instalador do Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Maxthon Core Update Service (MaxthonUpdateSvc) . (.Maxthon - No Comment.) - C:\Program Files\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) . (.Safer-Networking Ltd. - Spybot-S&D 2 Scanner Service.) - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) . (.Safer-Networking Ltd. - Spybot-S&D 2 Background update service.) - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) . (.Safer-Networking Ltd. - Windows Security Center integration..) - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe ~ Services: 11 Scanned in 00mn 20s ---\\ Enumeração Ativa do Ambiente de trabalho & Editor MHTML (024) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ Listagem dos dados do BootExecute (Bex) (034) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (sdnclean.exe) - File not found ~ BEX: 2 Scanned in 00mn 00s ---\\ Tarefas planificadas automaticamente (039) [MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152] [MD5.5B1AA494C27CF0BC3B03E8666ACB225E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4455704] [MD5.CBD4750B5096FA92EC0C51E3B9E1D3F6] [APT] [GarminUpdaterTask] (...) -- C:\Program Files\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [19456] [MD5.E1B44A75947137F4143308D566889837] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107848] [MD5.E1B44A75947137F4143308D566889837] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107848] [MD5.898E405EFEE2004C50F4FB0CE2580C5C] [APT] [Maxthon Update] (.Maxthon International ltd..) -- C:\Program Files\Maxthon\Bin\Maxthon.exe [257816] [MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984] [MD5.9CCE733E5262FB92C2331E8578512B49] [APT] [Check for updates] (.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe [4747720] [MD5.48FAE038F51676A795CEFAD780448D94] [APT] [Refresh immunization] (.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe [4460472] [MD5.280C014187E24860A7C860329513208F] [APT] [Scan the system] (.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe [4818848] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [992] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [992] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [996] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [996] ~ Scheduled Task: 13 Scanned in 00mn 12s ---\\ Componentes instalados (ActiveSetup Installed Components) (040) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Recursos do Windows Media Player.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API de tema do Windows.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Processador de comandos do Windows.) -- C:\Windows\system32\cmd.exe O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extensão da shell da pasta de FTP do Microsoft Internet Explore.) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Recursos do Windows Media Player.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitário de Inicialização por utilizador do IE.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL comum da shell do Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitário de Inicialização por utilizador do IE.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files\Google\Chrome\Application\43.0.2357.124\Installer\chrmstp.exe ~ Active Setup: 12 Scanned in 00mn 00s ---\\ Drivers lançados ao arranque do sistema (041) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Agendador de pacotes QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Controlador de Subsistema de Colocação em M.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys ~ Drivers: 60 Scanned in 00mn 01s ---\\ Software instalados (042) O42 - Logiciel: ANT Drivers Installer x86 - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {406EFA00-010D-48CA-A506-D55CE54AAF0A} O42 - Logiciel: Ace Stream Media 3.0.12 - (.Ace Stream Media.) [HKCU] -- AceStream O42 - Logiciel: Acer System Information - (.Acer.) [HKLM] -- {72199E33-4F2A-4B7F-8E25-95DDDD50A678} O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI O42 - Logiciel: Adobe Reader XI (11.0.11) - Português - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1046-7B44-AB0000000001} O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130} O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {28ED482A-56DB-47D9-8D9E-990FA8CD7D3D} O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc O42 - Logiciel: BTNext Legacy - (...) [HKLM] -- BTNext Legacy O42 - Logiciel: BitTorrent - (.BitTorrent Inc..) [HKCU] -- BitTorrent =>P2P.BitTorrent O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {8D7133DE-27D2-47E5-B248-4180278D32AA} O42 - Logiciel: Championship Manager 01-02 - (...) [HKLM] -- Championship Manager 01-02 O42 - Logiciel: Elevated Installer - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {0C262DA4-9A45-4154-976D-7AE94109DC4F} O42 - Logiciel: FairBot - (.Binteko Software.) [HKLM] -- FairBot_is1 O42 - Logiciel: Garmin Express - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {3ee9d193-ab0b-47f1-a31c-cce4678679ce} =>.Garmin Corporation O42 - Logiciel: Garmin Express - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {A6227383-A4A9-4486-BB79-34AEBC34D987} =>.Garmin Corporation O42 - Logiciel: Garmin Express Tray - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {557486A3-48C6-426E-A717-358A75DD27D9} =>.Garmin Corporation O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} O42 - Logiciel: Java 8 Update 40 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218040F0} O42 - Logiciel: Kodi - (.XBMC-Foundation.) [HKCU] -- Kodi O42 - Logiciel: Malwarebytes Anti-Malware versão 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 O42 - Logiciel: Maxthon Cloud Browser - (.Maxthon International Limited.) [HKLM] -- Maxthon3 O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {6E3939AE-9996-4D07-9A30-14C78AE93576} O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client O42 - Logiciel: MiniTool Partition Wizard Home Edition 8.1.1 - (.MiniTool Solution Ltd..) [HKLM] -- {05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1 O42 - Logiciel: Mozilla Firefox 38.0.5 (x86 pt-PT) - (.Mozilla.) [HKLM] -- Mozilla Firefox 38.0.5 (x86 pt-PT) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: OpenOffice 4.1.1 - (.Apache Software Foundation.) [HKLM] -- {5E695922-BB22-41F8-8C92-36490C29D65E} O42 - Logiciel: PDF Architect 2 - (.pdfforge GmbH.) [HKLM] -- PDF Architect 2 O42 - Logiciel: PDF Architect 2 View Module - (.pdfforge GmbH.) [HKLM] -- {D691E998-CF53-4F6C-AC20-E4284660E0E7} O42 - Logiciel: PDFCreator - (.pdfforge.) [HKLM] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} O42 - Logiciel: Pacote de controladores do Windows - Dynastream Innovations, Inc. ANT LibUS - (.Dynastream Innovations, Inc..) [HKLM] -- F9D2A789F9CFF8CEC36B544F53877C80F1F73C46 O42 - Logiciel: Pacote de controladores do Windows - Silicon Labs Software (DSI_SiUSBXp_3_1 - (.Silicon Labs Software.) [HKLM] -- D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2 O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} O42 - Logiciel: SDFormatter - (.SD Association.) [HKLM] -- {179324FF-7B16-4BA8-9836-055CAAEE4F08} O42 - Logiciel: SMSC Fast Infrared Driver - (.SMSC.) [HKLM] -- {1AEC7728-1640-4E98-AABC-5EBE3FB57FE4} O42 - Logiciel: SopCast 3.9.6 - (.www.sopcast.com.) [HKLM] -- SopCast O42 - Logiciel: Speccy - (.Piriform.) [HKLM] -- Speccy O42 - Logiciel: Spybot - Search & Destroy - (.Safer-Networking Ltd..) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1 O42 - Logiciel: Suporte para Aplicações Apple (32-bits) - (.Apple Inc..) [HKLM] -- {2FE00055-C4F3-4F7A-AEDD-E198D54CF12F} O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: TeamSpeak 3 Client - (.TeamSpeak Systems GmbH.) [HKLM] -- TeamSpeak 3 Client O42 - Logiciel: Traderline - (.Traderline.) [HKLM] -- {E31E2EAA-E062-43DE-8CF5-330F0C7C4BC6} O42 - Logiciel: VLC media player 2.1.3 - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN O42 - Logiciel: Win32DiskImager version 0.9.5 - (.ImageWriter Developers.) [HKLM] -- {D074CE74-912A-4AD3-A0BF-3937D9D01F17}_is1 O42 - Logiciel: WinRAR 5.01 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {B8032A6B-C4D0-4744-B75F-9DDCB56B5C6F} O42 - Logiciel: pdfforge Images2PDF 0.9.7.1125 - (.pdfforge.) [HKLM] -- {00120495-F25C-4F44-9DC7-2D812D025DBA} ~ Logic: 36 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\ATI Technologies Inc.] [HKCU\Software\ATI] [HKCU\Software\Acer] [HKCU\Software\Adobe] [HKCU\Software\AppDataLow\Software\JavaSoft] [HKCU\Software\AppDataLow] [HKCU\Software\Apple Computer, Inc.] [HKCU\Software\Apple Inc.] [HKCU\Software\BTNext Legacy] [HKCU\Software\Binteko Software] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\Cygwin] [HKCU\Software\DT Soft] [HKCU\Software\Garmin] [HKCU\Software\Google] [HKCU\Software\JavaSoft] [HKCU\Software\Licenses] [HKCU\Software\MEOCloud] [HKCU\Software\MTK] [HKCU\Software\Macromedia] [HKCU\Software\Maxthon3] [HKCU\Software\MiniTool Solution Ltd.] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\OpenOffice] [HKCU\Software\Opera Software] [HKCU\Software\PDF Architect 2] [HKCU\Software\PDFCreator] [HKCU\Software\PTC] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\QtProject] [HKCU\Software\RegisteredApplications] [HKCU\Software\Resplendence Sp] [HKCU\Software\Safer Networking Limited] [HKCU\Software\Synaptics] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\Volcano_Tool] [HKCU\Software\WinRAR SFX] [HKCU\Software\WinRAR] [HKCU\Software\XinYi Network] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\redsn0w] [HKCU\Software\systweak] [HKLM\Software\AMD] [HKLM\Software\ATI Technologies] [HKLM\Software\ATI] [HKLM\Software\Adobe] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\Apple Inc.] [HKLM\Software\CBSTEST] [HKLM\Software\CXT] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\DT Soft] [HKLM\Software\ENE Technology Inc] [HKLM\Software\GEAR Software] [HKLM\Software\Garmin] [HKLM\Software\Google] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Macromedia] [HKLM\Software\Malwarebytes' Anti-Malware] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\ODBC] [HKLM\Software\OpenOffice] [HKLM\Software\Opera Software] [HKLM\Software\PDFCreator] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\RegisteredApplications] [HKLM\Software\SAMSUNG] [HKLM\Software\SMSC] [HKLM\Software\Safer Networking Limited] [HKLM\Software\Sonic] [HKLM\Software\Sports Interactive Ltd] [HKLM\Software\Synaptics] [HKLM\Software\Systweak] [HKLM\Software\VideoLAN] [HKLM\Software\Volatile] [HKLM\Software\WOW6432Node] [HKLM\Software\WinRAR] [HKLM\Software\XinYi Network] [HKLM\Software\mozilla.org] ~ Key Software: 186 Scanned in 00mn 00s ---\\ Conteúdo das pastas Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 12-07-2014 - 19:06:34 - [] ----D C:\Program Files\Acer O43 - CFD: 01-10-2014 - 18:50:00 - [] ----D C:\Program Files\Adobe O43 - CFD: 13-07-2014 - 02:00:16 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc O43 - CFD: 12-07-2014 - 15:09:46 - [] ----D C:\Program Files\ATI O43 - CFD: 12-07-2014 - 15:18:41 - [] ----D C:\Program Files\ATI Technologies O43 - CFD: 13-07-2014 - 01:59:40 - [] ----D C:\Program Files\Bonjour O43 - CFD: 03-04-2015 - 03:29:07 - [] ----D C:\Program Files\BTNext Legacy O43 - CFD: 12-07-2014 - 19:48:35 - [] ----D C:\Program Files\CCleaner O43 - CFD: 07-03-2015 - 20:34:18 - [] ----D C:\Program Files\Common Files O43 - CFD: 19-07-2014 - 14:17:04 - [] ----D C:\Program Files\DAEMON Tools Lite =>.DT Soft Ltd O43 - CFD: 12-04-2015 - 13:42:34 - [] ----D C:\Program Files\DIFX O43 - CFD: 12-04-2011 - 06:40:46 - [] ----D C:\Program Files\DVD Maker O43 - CFD: 25-08-2014 - 17:02:08 - [] ----D C:\Program Files\FairBot O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\Program Files\Ficheiros comuns O43 - CFD: 30-04-2015 - 03:58:03 - [] ----D C:\Program Files\Garmin O43 - CFD: 27-04-2015 - 20:30:28 - [] ----D C:\Program Files\Google O43 - CFD: 02-10-2014 - 00:09:09 - [] ----D C:\Program Files\ImageWriter O43 - CFD: 25-08-2014 - 19:52:24 - [0] --H-D C:\Program Files\InstallJammer Registry O43 - CFD: 18-04-2015 - 13:39:11 - [] --H-D C:\Program Files\InstallShield Installation Information O43 - CFD: 13-06-2015 - 14:22:12 - [] ----D C:\Program Files\Internet Explorer O43 - CFD: 04-02-2015 - 21:04:07 - [] ----D C:\Program Files\iPod O43 - CFD: 04-02-2015 - 21:05:06 - [] ----D C:\Program Files\iTunes O43 - CFD: 07-03-2015 - 20:34:53 - [] ----D C:\Program Files\Java O43 - CFD: 22-04-2015 - 19:50:10 - [] ----D C:\Program Files\Kodi O43 - CFD: 30-05-2015 - 19:57:21 - [] ----D C:\Program Files\Malwarebytes Anti-Malware O43 - CFD: 26-05-2015 - 21:14:36 - [] ----D C:\Program Files\Maxthon O43 - CFD: 12-04-2011 - 06:40:44 - [] ----D C:\Program Files\Microsoft Games O43 - CFD: 11-06-2015 - 20:39:12 - [] ----D C:\Program Files\Microsoft Security Client O43 - CFD: 12-07-2014 - 19:44:20 - [] ----D C:\Program Files\Microsoft.NET O43 - CFD: 02-10-2014 - 20:14:10 - [] ----D C:\Program Files\MiniTool Partition Wizard Home Edition 8.1.1 O43 - CFD: 14-06-2015 - 13:58:31 - [] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 14-06-2015 - 13:58:31 - [] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 14-07-2009 - 05:52:30 - [] ----D C:\Program Files\MSBuild O43 - CFD: 15-11-2014 - 17:34:45 - [] ----D C:\Program Files\OpenOffice 4 O43 - CFD: 27-04-2015 - 20:30:13 - [] ----D C:\Program Files\Opera O43 - CFD: 28-09-2014 - 12:26:57 - [] ----D C:\Program Files\OtterBrowser O43 - CFD: 01-11-2014 - 14:12:35 - [] ----D C:\Program Files\PDF Architect 2 O43 - CFD: 02-11-2014 - 04:05:57 - [] ----D C:\Program Files\PDFCreator O43 - CFD: 01-11-2014 - 14:08:43 - [] ----D C:\Program Files\pdfforge O43 - CFD: 25-10-2014 - 03:09:23 - [] ----D C:\Program Files\PTC O43 - CFD: 14-07-2009 - 05:52:30 - [] ----D C:\Program Files\Reference Assemblies O43 - CFD: 11-02-2015 - 18:45:07 - [] ----D C:\Program Files\SAMSUNG O43 - CFD: 02-10-2014 - 00:11:13 - [] ----D C:\Program Files\SDA O43 - CFD: 18-04-2015 - 13:39:14 - [] ----D C:\Program Files\SMSC O43 - CFD: 06-05-2015 - 02:58:39 - [] ----D C:\Program Files\SopCast O43 - CFD: 16-07-2014 - 16:45:05 - [] ----D C:\Program Files\Speccy O43 - CFD: 30-05-2015 - 02:09:32 - [] ----D C:\Program Files\Spybot - Search & Destroy 2 O43 - CFD: 24-12-2014 - 03:35:34 - [] ----D C:\Program Files\Steam O43 - CFD: 12-07-2014 - 19:10:39 - [] ----D C:\Program Files\Synaptics O43 - CFD: 26-08-2014 - 16:23:52 - [] ----D C:\Program Files\TeamSpeak 3 Client O43 - CFD: 30-12-2014 - 20:46:06 - [] ----D C:\Program Files\Traderline O43 - CFD: 14-07-2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 12-07-2014 - 15:38:15 - [] ----D C:\Program Files\VideoLAN O43 - CFD: 11-02-2015 - 20:46:42 - [0] ----D C:\Program Files\VROOT O43 - CFD: 12-07-2014 - 20:03:49 - [] ----D C:\Program Files\WhoCrashed O43 - CFD: 12-07-2014 - 16:42:07 - [] ----D C:\Program Files\Windows Defender O43 - CFD: 13-06-2015 - 14:22:10 - [] ----D C:\Program Files\Windows Journal O43 - CFD: 12-04-2011 - 06:31:31 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 13-06-2015 - 14:22:09 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 12-07-2014 - 15:03:38 - [] ----D C:\Program Files\Windows NT O43 - CFD: 26-05-2013 - 21:29:37 - [] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 20-11-2010 - 22:33:48 - [] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 13-07-2014 - 19:34:11 - [] ----D C:\Program Files\Windows Sidebar O43 - CFD: 12-07-2014 - 15:38:05 - [] ----D C:\Program Files\WinRAR O43 - CFD: 14-06-2015 - 19:49:21 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman O43 - CFD: 01-10-2014 - 18:51:12 - [] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 04-02-2015 - 21:04:05 - [] ----D C:\Program Files\Common Files\Apple O43 - CFD: 07-03-2015 - 20:34:18 - [] ----D C:\Program Files\Common Files\Java O43 - CFD: 13-07-2014 - 03:02:24 - [] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 14-07-2009 - 03:37:05 - [] ----D C:\Program Files\Common Files\Services O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\Program Files\Common Files\Sistema O43 - CFD: 14-07-2009 - 03:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 13-07-2014 - 19:34:11 - [] ----D C:\Program Files\Common Files\System O43 - CFD: 04-02-2015 - 21:03:48 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 O43 - CFD: 15-11-2014 - 18:29:29 - [] ----D C:\ProgramData\Adobe O43 - CFD: 22-08-2014 - 18:09:34 - [] ----D C:\ProgramData\AGeeksToy O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\ProgramData\Ambiente de trabalho O43 - CFD: 13-07-2014 - 02:00:11 - [] ----D C:\ProgramData\Apple O43 - CFD: 19-01-2015 - 00:47:03 - [] ----D C:\ProgramData\Apple Computer O43 - CFD: 14-07-2009 - 05:53:55 - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 12-07-2014 - 15:25:16 - [] ----D C:\ProgramData\ATI O43 - CFD: 04-02-2015 - 21:05:07 - [] ----D C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB O43 - CFD: 19-07-2014 - 14:15:33 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd O43 - CFD: 14-07-2009 - 05:53:55 - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\ProgramData\Documentos O43 - CFD: 14-07-2009 - 05:53:55 - [] -SH-D C:\ProgramData\Documents O43 - CFD: 14-07-2009 - 05:53:55 - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\ProgramData\Favoritos O43 - CFD: 12-04-2015 - 13:40:26 - [] ----D C:\ProgramData\Garmin O43 - CFD: 30-05-2015 - 19:56:37 - [] ----D C:\ProgramData\Malwarebytes O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\ProgramData\Menu Iniciar O43 - CFD: 30-05-2015 - 02:00:33 - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 12-07-2014 - 15:03:38 - [] -SH-D C:\ProgramData\Modelos O43 - CFD: 12-07-2014 - 15:29:12 - [] ----D C:\ProgramData\Mozilla O43 - CFD: 07-03-2015 - 20:32:10 - [] ----D C:\ProgramData\Oracle O43 - CFD: 30-04-2015 - 03:59:09 - [] ----D C:\ProgramData\Package Cache O43 - CFD: 01-11-2014 - 14:10:51 - [] ----D C:\ProgramData\PDF Architect 2 O43 - CFD: 11-02-2015 - 18:43:50 - [] ----D C:\ProgramData\Samsung O43 - CFD: 30-05-2015 - 02:17:44 - [] ----D C:\ProgramData\Spybot - Search & Destroy O43 - CFD: 15-09-2014 - 16:33:24 - [] ----D C:\ProgramData\SP_FT_Logs O43 - CFD: 31-08-2014 - 16:50:38 - [] ----D C:\ProgramData\SP_MDT_Logs O43 - CFD: 14-07-2009 - 05:53:55 - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 19-07-2014 - 15:43:19 - [] ----D C:\ProgramData\Sun O43 - CFD: 14-07-2009 - 05:53:55 - [] -SH-D C:\ProgramData\Templates O43 - CFD: 12-07-2014 - 14:48:46 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 12-07-2014 - 14:49:05 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 25-08-2014 - 19:52:24 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetMarket Trader O43 - CFD: 15-07-2014 - 16:41:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BTNext Legacy O43 - CFD: 12-07-2014 - 15:18:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center O43 - CFD: 12-07-2014 - 19:48:33 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 02-06-2015 - 18:20:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Championship Manager 01-02 O43 - CFD: 25-08-2014 - 17:02:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FairBot O43 - CFD: 12-07-2014 - 14:49:05 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 30-04-2015 - 03:56:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin O43 - CFD: 27-04-2015 - 20:31:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 02-10-2014 - 00:09:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer O43 - CFD: 04-02-2015 - 21:05:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes O43 - CFD: 19-11-2014 - 20:30:54 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 14-07-2009 - 05:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 30-05-2015 - 19:59:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 26-05-2015 - 21:14:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxthon Cloud Browser O43 - CFD: 15-09-2014 - 23:19:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Home Edition 8.1.1 O43 - CFD: 15-11-2014 - 17:36:42 - [] -S--D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 O43 - CFD: 01-11-2014 - 14:12:45 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2 O43 - CFD: 01-11-2014 - 14:10:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator O43 - CFD: 01-11-2014 - 14:08:47 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdfforge O43 - CFD: 02-10-2014 - 00:11:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter O43 - CFD: 06-05-2015 - 02:58:38 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast O43 - CFD: 30-05-2015 - 02:00:37 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 O43 - CFD: 14-07-2009 - 05:41:57 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 12-04-2011 - 06:40:37 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 26-08-2014 - 16:23:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client O43 - CFD: 12-07-2014 - 15:38:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 12-07-2014 - 15:38:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 14-06-2015 - 19:49:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman O43 - CFD: 16-05-2015 - 19:54:39 - [] ----D C:\Users\João\AppData\Roaming\.ACEStream O43 - CFD: 03-05-2015 - 19:40:46 - [] ----D C:\Users\João\AppData\Roaming\ACEStream O43 - CFD: 03-05-2015 - 19:39:18 - [] ----D C:\Users\João\AppData\Roaming\AceWebExtension O43 - CFD: 01-10-2014 - 18:53:12 - [] ----D C:\Users\João\AppData\Roaming\Adobe O43 - CFD: 27-07-2014 - 13:27:29 - [] ----D C:\Users\João\AppData\Roaming\Apple Computer O43 - CFD: 12-07-2014 - 15:25:16 - [] ----D C:\Users\João\AppData\Roaming\ATI O43 - CFD: 25-08-2014 - 17:02:32 - [] ----D C:\Users\João\AppData\Roaming\Binteko Software O43 - CFD: 30-05-2015 - 02:31:08 - [] ----D C:\Users\João\AppData\Roaming\BitTorrent =>P2P.BitTorrent O43 - CFD: 13-06-2015 - 12:37:16 - [] ----D C:\Users\João\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd O43 - CFD: 12-04-2015 - 13:41:53 - [] ----D C:\Users\João\AppData\Roaming\Garmin O43 - CFD: 18-04-2015 - 13:35:54 - [] ----D C:\Users\João\AppData\Roaming\InstallShield O43 - CFD: 13-05-2015 - 17:44:32 - [] ----D C:\Users\João\AppData\Roaming\Kodi O43 - CFD: 13-07-2014 - 01:59:49 - [] ----D C:\Users\João\AppData\Roaming\Macromedia O43 - CFD: 26-05-2015 - 21:17:56 - [] ----D C:\Users\João\AppData\Roaming\Maxthon3 O43 - CFD: 12-04-2011 - 06:40:37 - [0] ----D C:\Users\João\AppData\Roaming\Media Center Programs O43 - CFD: 12-05-2015 - 17:26:07 - [] -S--D C:\Users\João\AppData\Roaming\Microsoft O43 - CFD: 12-07-2014 - 15:29:28 - [] ----D C:\Users\João\AppData\Roaming\Mozilla O43 - CFD: 15-11-2014 - 17:37:36 - [] ----D C:\Users\João\AppData\Roaming\OpenOffice O43 - CFD: 15-09-2014 - 21:12:37 - [] ----D C:\Users\João\AppData\Roaming\Oracle O43 - CFD: 01-11-2014 - 14:08:43 - [] ----D C:\Users\João\AppData\Roaming\pdfforge O43 - CFD: 13-06-2015 - 11:51:07 - [] ----D C:\Users\João\AppData\Roaming\vlc O43 - CFD: 12-07-2014 - 19:09:19 - [] ----D C:\Users\João\AppData\Roaming\WinRAR O43 - CFD: 14-06-2015 - 19:50:45 - [] ----D C:\Users\João\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 21-03-2015 - 14:20:32 - [] ----D C:\Users\João\AppData\Local\Adobe O43 - CFD: 22-08-2014 - 18:09:34 - [0] ----D C:\Users\João\AppData\Local\AGeeksToy O43 - CFD: 13-07-2014 - 02:00:19 - [] ----D C:\Users\João\AppData\Local\Apple O43 - CFD: 13-07-2014 - 02:09:46 - [] ----D C:\Users\João\AppData\Local\Apple Computer O43 - CFD: 12-07-2014 - 15:04:58 - [] -SH-D C:\Users\João\AppData\Local\Application Data O43 - CFD: 12-07-2014 - 15:25:16 - [] ----D C:\Users\João\AppData\Local\ATI O43 - CFD: 15-07-2014 - 18:26:36 - [] ----D C:\Users\João\AppData\Local\Chromium O43 - CFD: 02-06-2015 - 17:35:04 - [] ----D C:\Users\João\AppData\Local\Diagnostics O43 - CFD: 02-10-2014 - 00:10:15 - [] ----D C:\Users\João\AppData\Local\Downloaded Installations O43 - CFD: 02-06-2015 - 17:53:00 - [] ----D C:\Users\João\AppData\Local\ElevatedDiagnostics O43 - CFD: 31-01-2015 - 14:18:20 - [] -SH-D C:\Users\João\AppData\Local\EmieBrowserModeList O43 - CFD: 12-07-2014 - 20:43:11 - [] -SH-D C:\Users\João\AppData\Local\EmieSiteList O43 - CFD: 12-07-2014 - 20:43:11 - [] -SH-D C:\Users\João\AppData\Local\EmieUserList O43 - CFD: 06-05-2015 - 02:17:03 - [] ----D C:\Users\João\AppData\Local\Garmin_Ltd._or_its_subsid O43 - CFD: 27-04-2015 - 20:31:07 - [] ----D C:\Users\João\AppData\Local\Google O43 - CFD: 12-07-2014 - 15:04:58 - [] -SH-D C:\Users\João\AppData\Local\Histórico O43 - CFD: 13-07-2014 - 01:59:49 - [] ----D C:\Users\João\AppData\Local\Macromedia O43 - CFD: 05-09-2014 - 12:59:15 - [] ----D C:\Users\João\AppData\Local\Microsoft O43 - CFD: 12-07-2014 - 20:54:18 - [] ----D C:\Users\João\AppData\Local\Microsoft Games O43 - CFD: 19-01-2015 - 00:46:02 - [] ----D C:\Users\João\AppData\Local\Mozilla O43 - CFD: 28-09-2014 - 12:24:06 - [] ----D C:\Users\João\AppData\Local\Otter O43 - CFD: 12-07-2014 - 15:50:10 - [] ----D C:\Users\João\AppData\Local\Programs O43 - CFD: 19-10-2014 - 23:03:26 - [] ----D C:\Users\João\AppData\Local\PTC O43 - CFD: 29-04-2015 - 02:01:20 - [] ----D C:\Users\João\AppData\Local\Sports Interactive O43 - CFD: 14-06-2015 - 19:50:43 - [] ----D C:\Users\João\AppData\Local\Temp O43 - CFD: 12-07-2014 - 15:04:58 - [] -SH-D C:\Users\João\AppData\Local\Temporary Internet Files O43 - CFD: 31-08-2014 - 01:41:36 - [] ----D C:\Users\João\AppData\Local\Trolltech O43 - CFD: 13-06-2015 - 13:29:03 - [] ----D C:\Users\João\AppData\Local\VirtualStore O43 - CFD: 14-07-2009 - 05:42:04 - [] R---D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 03-05-2015 - 19:37:43 - [] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media O43 - CFD: 12-07-2014 - 19:06:34 - [] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acer O43 - CFD: 13-06-2015 - 14:30:44 - [] R---D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 15-07-2014 - 16:41:32 - [0] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BTNext Legacy O43 - CFD: 22-04-2015 - 19:50:11 - [] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi O43 - CFD: 14-07-2009 - 05:37:42 - [] R---D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 06-05-2015 - 02:58:23 - [0] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast O43 - CFD: 13-06-2015 - 14:30:44 - [] R---D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 30-12-2014 - 20:45:49 - [] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Traderline O43 - CFD: 12-07-2014 - 15:38:05 - [] ----D C:\Users\João\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ~ Program Folder: 197 Scanned in 00mn 02s ---\\ Últimos ficheiros alterados ou criados no Windows e Sistema32 (044) O44 - LFC:[MD5.AD2726E4A53EC118D88CCA40260E1AE0] - 02-06-2015 - 19:35:47 ---A- . (.Microsoft Corporation - IEAK branding.) -- C:\Windows\System32\iedkcs32.dll [342728] O44 - LFC:[MD5.78492CF3C3697FB5AF4EAABB2BAF8595] - 11-06-2015 - 18:20:30 ---A- . (.Microsoft Corporation - XML Resources.) -- C:\Windows\System32\msxml3r.dll [2048] O44 - LFC:[MD5.DA5B856A037872BE089CA6967C7050C5] - 11-06-2015 - 18:20:31 ---A- . (.Microsoft Corporation - MSXML 3.0 SP11.) -- C:\Windows\System32\msxml3.dll [1237504] O44 - LFC:[MD5.58788565442368B0615DDAF1D452B843] - 11-06-2015 - 18:21:20 ---A- . (.Microsoft Corporation - Biblioteca de Controlos de Experiência de U.) -- C:\Windows\System32\comctl32.dll [530432] O44 - LFC:[MD5.04A946513FD3BAAD7160E3618D28518B] - 11-06-2015 - 18:27:47 ---A- . (.Microsoft Corporation - Motor do ‘Editor de configuração de seguran.) -- C:\Windows\System32\scesrv.dll [308224] O44 - LFC:[MD5.306EB846F88E58C7E763946DE95952E3] - 11-06-2015 - 18:34:30 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [46592] O44 - LFC:[MD5.AA8E25A6ED527C64F12AA06857B344D4] - 11-06-2015 - 18:34:31 ---A- . (.Microsoft Corporation - Detecção Automática da Localização na Rede.) -- C:\Windows\System32\nlasvc.dll [242688] O44 - LFC:[MD5.71CAE7E61FD7C841481AB92A8BE6DED1] - 11-06-2015 - 18:34:31 ---A- . (.Microsoft Corporation - Indicador de Estado de Conectividade de Red.) -- C:\Windows\System32\ncsi.dll [162304] O44 - LFC:[MD5.67E40B09B3641B2EBBEFF225A820F1F9] - 11-06-2015 - 18:34:32 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll [3072] O44 - LFC:[MD5.C77D35AF70322CDC411EBF708367B5D4] - 11-06-2015 - 18:34:32 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll [4096] O44 - LFC:[MD5.78945E981923CE405F70865FFEF62A11] - 11-06-2015 - 18:34:32 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll [4608] O44 - LFC:[MD5.94C8A2A7AB5E2FBD3A27E5FE2F9F4A5F] - 11-06-2015 - 18:34:32 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll [3072] O44 - LFC:[MD5.EF0293BC77459AEB69196965D1A99F63] - 11-06-2015 - 18:34:32 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll [6144] O44 - LFC:[MD5.E2C57904CFCD10F80E3FFB8CAC016988] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll [3072] O44 - LFC:[MD5.FAA383ABE08197DC77461EB3ECA2991D] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll [3072] O44 - LFC:[MD5.59956C7528397B6744A9DEDE0574554C] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll [3072] O44 - LFC:[MD5.5AC5BE4AC1C311028545B86770614D83] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll [5120] O44 - LFC:[MD5.151D72CCD292B83B82BE9352F11AEAB2] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll [3072] O44 - LFC:[MD5.07E9483EF2D8F02B65412E5038D47A7E] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll [3584] O44 - LFC:[MD5.88C6520D84B8955EC5C3CFF7E18D0A04] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll [3584] O44 - LFC:[MD5.2298F06520079AFD5B5E94032DB6D3D9] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll [3072] O44 - LFC:[MD5.983AF1FDD1A9AE4FCF2388C4D12DEB97] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll [3584] O44 - LFC:[MD5.88B5EF564A5D60220FDFA91BB5B09CDA] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll [3584] O44 - LFC:[MD5.CDD2F089540ECDF3634B8AFC2CA0CDCD] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll [3584] O44 - LFC:[MD5.93F75DAA99880C03022958E0275226A0] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll [3584] O44 - LFC:[MD5.7BC534E0BC9075A7EEBEA0AAAEAF7733] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll [3072] O44 - LFC:[MD5.D8A8A617D95C9A345D27064AAF247545] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll [3072] O44 - LFC:[MD5.881F453F4C024BDF4C85BEC22E47BCE8] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll [3072] O44 - LFC:[MD5.C2B9E1259B8DF2B3469FDAE0235C9733] - 11-06-2015 - 18:34:33 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll [3584] O44 - LFC:[MD5.7B6EAC99F571A2D99777FD2DD7B38490] - 11-06-2015 - 18:34:34 ---A- . (.Microsoft Corporation - Anfitrião de Janelas de Consola.) -- C:\Windows\System32\conhost.exe [271360] O44 - LFC:[MD5.76157175E9A5FB843997A2284BDDC10A] - 11-06-2015 - 18:34:34 ---A- . (.Microsoft Corporation - DLL cliente da API BASE do Windows NT.) -- C:\Windows\System32\KernelBase.dll [293888] O44 - LFC:[MD5.8D5CC74BFA8F947CB283527806DB7B1F] - 11-06-2015 - 18:34:34 ---A- . (.Microsoft Corporation - DLL cliente da API BASE do Windows NT.) -- C:\Windows\System32\kernel32.dll [872448] O44 - LFC:[MD5.33A704DE3BB90C86968767FC4D2A0D53] - 11-06-2015 - 18:34:34 ---A- . (.Microsoft Corporation - DLL de servidor do Windows Multiutilizador.) -- C:\Windows\System32\winsrv.dll [171008] O44 - LFC:[MD5.B6E7AA777BDA6F8A6AC4AE08D5E3FB84] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll [3072] O44 - LFC:[MD5.12C0AF9DDB747DF658DA8136392706DB] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll [3072] O44 - LFC:[MD5.580DE158E2D006EF5B999C136F0E6082] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll [4096] O44 - LFC:[MD5.1A46FC30934CB82591391912F4C0C44B] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll [4096] O44 - LFC:[MD5.1242EF5A3E068F908AF739FD3C8F0097] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll [4608] O44 - LFC:[MD5.58B29023E5DE7E4E7944861C99A17BFB] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll [4096] O44 - LFC:[MD5.8AA0008A000CF2742F30FCFB98570C11] - 11-06-2015 - 18:34:34 --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll [4096] O44 - LFC:[MD5.C28B7C4F7086FDC5A394D8CCB8454504] - 11-06-2015 - 18:34:36 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [34304] O44 - LFC:[MD5.65CD7BFF5E940F95F2028570594CA834] - 11-06-2015 - 18:34:36 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [299008] O44 - LFC:[MD5.BD4E7F9B2EF10A1FD41A79D80AA33738] - 11-06-2015 - 18:34:36 ---A- . (.Microsoft Corporation - DCI Manager.) -- C:\Windows\System32\dciman32.dll [10240] O44 - LFC:[MD5.F0BED78C9DC4387F4C4FCCF891A7BBAB] - 11-06-2015 - 18:34:36 ---A- . (.Microsoft Corporation - Font Subsetting DLL.) -- C:\Windows\System32\fontsub.dll [70656] O44 - LFC:[MD5.AB4B8F91C6D0566304A241EC9DA8EA21] - 11-06-2015 - 18:34:36 ---A- . (.Microsoft Corporation - Language Pack.) -- C:\Windows\System32\lpk.dll [26624] O44 - LFC:[MD5.20D035F5A92F5C12CB8694FAE5C30194] - 11-06-2015 - 18:34:36 ---A- . (.Microsoft Corporation - Web DAV Client DLL.) -- C:\Windows\System32\davclnt.dll [87552] O44 - LFC:[MD5.049FAF4EE26617B4CFCE3C4F45953C16] - 11-06-2015 - 18:34:36 ---A- . (.Microsoft Corporation - Web DAV Service DLL.) -- C:\Windows\System32\WebClnt.dll [210432] O44 - LFC:[MD5.1C3EBF74425637371DD208B67381A949] - 11-06-2015 - 18:34:36 ---A- . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\Drivers\mrxdav.sys [116736] O44 - LFC:[MD5.DEC1A1361B15C498701AD4DAFF0C5516] - 11-06-2015 - 18:34:38 ---A- . (.Microsoft Corporation - DLL comum da shell do Windows.) -- C:\Windows\System32\shell32.dll [12878336] O44 - LFC:[MD5.38D29935EC137D25985BAFFDD2F2A16F] - 11-06-2015 - 18:35:18 ---A- . (.Microsoft Corporation - DLL de Erro do Media Foundation.) -- C:\Windows\System32\mferror.dll [2048] O44 - LFC:[MD5.F0C8038C9336EE6C3244CF431AB362BE] - 11-06-2015 - 18:35:18 ---A- . (.Microsoft Corporation - Recursos de Evento do Auxiliar de Compatibi.) -- C:\Windows\System32\pcaevts.dll [8704] O44 - LFC:[MD5.15EE088A2ECEBD474D5748691C0FA5D2] - 11-06-2015 - 18:35:19 ---A- . (.Microsoft Corporation - Mount Point Manger Sysprep Utility Library.) -- C:\Windows\System32\msmmsp.dll [10752] O44 - LFC:[MD5.A6AEADE370FFE3F37554D8AAA3E4B873] - 11-06-2015 - 18:35:20 ---A- . (.Microsoft Corporation - Auxiliar de Compatibilidade de Programas.) -- C:\Windows\System32\pcalua.exe [8192] O44 - LFC:[MD5.781DD44F6C99BFCCEE5B2320BBB0783B] - 11-06-2015 - 18:35:20 ---A- . (.Microsoft Corporation - Media Foundation Crash Dump Encryption DLL.) -- C:\Windows\System32\EncDump.dll [275968] O44 - LFC:[MD5.10495B2681F3E271CB93608D853A0CF0] - 11-06-2015 - 18:35:20 ---A- . (.Microsoft Corporation - Program Compatibility Assistant Helper.) -- C:\Windows\System32\pcawrk.exe [9728] O44 - LFC:[MD5.0C5C3F60FBB14056439D2649B2A5CDEE] - 11-06-2015 - 18:35:20 ---A- . (.Microsoft Corporation - Sessão de Áudio.) -- C:\Windows\System32\AudioSes.dll [195584] O44 - LFC:[MD5.725F19C6D3C3DBA854DB304CF371AB68] - 11-06-2015 - 18:35:21 ---A- . (.Microsoft Corporation - Audio Ks Endpoint.) -- C:\Windows\System32\AUDIOKSE.dll [442880] O44 - LFC:[MD5.39417BFC4939F1DC2D36C317FB714895] - 11-06-2015 - 18:35:21 ---A- . (.Microsoft Corporation - EXE do Media Foundation Protected Pipeline.) -- C:\Windows\System32\mfpmp.exe [23040] O44 - LFC:[MD5.C45E651DD6C0D7C1D92B338CE9331EF3] - 11-06-2015 - 18:35:21 ---A- . (.Microsoft Corporation - Program Compatibility Assistant Diagnostic.) -- C:\Windows\System32\pcadm.dll [28160] O44 - LFC:[MD5.0D3D70EB35689D492F7C2593390BCD18] - 11-06-2015 - 18:35:22 ---A- . (.Microsoft Corporation - Audio Engine.) -- C:\Windows\System32\AudioEng.dll [374784] O44 - LFC:[MD5.70E96EBE87A38857619671FCB9C8EC7B] - 11-06-2015 - 18:35:23 ---A- . (.Microsoft Corporation - DRM ActiveX Network Object.) -- C:\Windows\System32\msnetobj.dll [265216] O44 - LFC:[MD5.CAEF84EB470BF5FC5FB782C636DFB4BB] - 11-06-2015 - 18:35:23 ---A- . (.Microsoft Corporation - Instalador R&R.) -- C:\Windows\System32\rrinstaller.exe [50176] O44 - LFC:[MD5.16D54687850F162F43FF0210EF41F5A0] - 11-06-2015 - 18:35:23 ---A- . (.Microsoft Corporation - Serviço de Áudio do Windows.) -- C:\Windows\System32\audiosrv.dll [475136] O44 - LFC:[MD5.7958A41D851B5270446F8937B894013F] - 11-06-2015 - 18:35:24 ---A- . (.Microsoft Corporation - Media Foundation Proxy DLL.) -- C:\Windows\System32\mfps.dll [103424] O44 - LFC:[MD5.C67B24577DEDA3896C8A20C68B694940] - 11-06-2015 - 18:35:24 ---A- . (.Microsoft Corporation - Windows Audio Device Graph Isolation.) -- C:\Windows\System32\audiodg.exe [100864] O44 - LFC:[MD5.320A8699369C43CF53B2DB4538D17C52] - 11-06-2015 - 18:35:24 ---A- . (.Microsoft Corporation - Windows Media Secure Content Provider.) -- C:\Windows\System32\msscp.dll [504320] O44 - LFC:[MD5.B54FD1991E659FD61EF1D34EC27AAECD] - 11-06-2015 - 18:35:26 ---A- . (.Microsoft Corporation - Cryptographic Service Provider API.) -- C:\Windows\System32\cryptsp.dll [81408] O44 - LFC:[MD5.B4867EA6A6BC23EBE4DB0839ED3E3DC2] - 11-06-2015 - 18:35:26 ---A- . (.Microsoft Corporation - Gestor de Ponto de Montagem.) -- C:\Windows\System32\Drivers\mountmgr.sys [78784] O44 - LFC:[MD5.25DB58A2C9B7A6E1E28D037A080BDBC7] - 11-06-2015 - 18:35:27 ---A- . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll [106496] O44 - LFC:[MD5.B7D2BB84C590F0AE9DA51DBB065A780E] - 11-06-2015 - 18:35:27 ---A- . (.Microsoft Corporation - Fornecedor Microsoft Trust UI.) -- C:\Windows\System32\cryptui.dll [1005056] O44 - LFC:[MD5.C5667EE72D7364BE81516C0707FEF724] - 11-06-2015 - 18:35:27 ---A- . (.Microsoft Corporation - Media Foundation Platform DLL.) -- C:\Windows\System32\mfplat.dll [354816] O44 - LFC:[MD5.52954BE460EC6C54C0ACB2B3B126FFC6] - 11-06-2015 - 18:35:27 ---A- . (.Microsoft Corporation - Serviço Auxiliar de Compatibilidade de Prog.) -- C:\Windows\System32\pcasvc.dll [157184] O44 - LFC:[MD5.2D4814D567E5A85C473228BA772A7AFB] - 11-06-2015 - 18:35:28 ---A- . (.Microsoft Corporation - DLL do Compositor de Vídeo Avançado.) -- C:\Windows\System32\evr.dll [489984] O44 - LFC:[MD5.98C1191C862B44567FCF3C18BAEE859E] - 11-06-2015 - 18:35:28 ---A- . (.Microsoft Corporation - DirectShow DVD PlayBack Runtime..) -- C:\Windows\System32\qdvd.dll [519680] O44 - LFC:[MD5.96DB6A923DEDB58FC7CBBF5CFF73314D] - 11-06-2015 - 18:35:28 ---A- . (.Microsoft Corporation - DirectShow Runtime..) -- C:\Windows\System32\quartz.dll [1329664] O44 - LFC:[MD5.8ADF8A3E63601BD185DE6BB459AF47F5] - 11-06-2015 - 18:35:28 ---A- . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\Drivers\cng.sys [370488] O44 - LFC:[MD5.7E0597765828ED3D171BC793C5B0B80D] - 11-06-2015 - 18:35:28 ---A- . (.Microsoft Corporation - Microsoft Trust Verification APIs.) -- C:\Windows\System32\wintrust.dll [179200] O44 - LFC:[MD5.C5A6D18A8F4E083B22604F587D4D1F5C] - 11-06-2015 - 18:35:29 ---A- . (.Microsoft Corporation - Code Integrity Module.) -- C:\Windows\System32\ci.dll [409272] O44 - LFC:[MD5.AEBC369F7DC72AB3F5B9BDF34FA0D43F] - 11-06-2015 - 18:35:29 ---A- . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\Drivers\PEAuth.sys [593920] O44 - LFC:[MD5.B97E16D36DB7B7DD22C97857506FA58A] - 11-06-2015 - 18:35:29 ---A- . (.Microsoft Corporation - Serviços de Criptografia.) -- C:\Windows\System32\cryptsvc.dll [145920] O44 - LFC:[MD5.A36E32E1835AEFC0305F782EE787D54B] - 11-06-2015 - 18:35:30 ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1175040] O44 - LFC:[MD5.BB73C907D1BD437B6C30F2C23BB089FC] - 11-06-2015 - 18:35:31 ---A- . (.Microsoft Corporation - DRM Migration DLL.) -- C:\Windows\System32\drmmgrtn.dll [406016] O44 - LFC:[MD5.11017F90E2EBCD12146CF6A611443657] - 11-06-2015 - 18:35:32 ---A- . (.Microsoft Corporation - DLL do Media Foundation.) -- C:\Windows\System32\mf.dll [3209728] O44 - LFC:[MD5.833FCABCB5D95B1911BA6E62FC82AC04] - 11-06-2015 - 18:35:35 ---A- . (.Microsoft Corporation - Windows Media DRM SDK DLL.) -- C:\Windows\System32\wmdrmsdk.dll [617984] O44 - LFC:[MD5.003C51B9FE38287BA4E0E58D3AE080BD] - 11-06-2015 - 18:35:36 ---A- . (.Microsoft Corporation - BlackBox DLL.) -- C:\Windows\System32\blackbox.dll [744960] O44 - LFC:[MD5.DCC148408770F2D55B201F8FC26438A1] - 11-06-2015 - 18:35:36 ---A- . (.Microsoft Corporation - DRMv2 Client DLL.) -- C:\Windows\System32\drmv2clt.dll [988160] O44 - LFC:[MD5.9566C8BBD2271A7962D4432A624762AD] - 11-06-2015 - 18:36:15 ---A- . (.Microsoft Corporation - Codec do Windows Media Photo.) -- C:\Windows\System32\WMPhoto.dll [417792] O44 - LFC:[MD5.33A60554882FDF59CDA3E1806370BBA1] - 11-06-2015 - 18:36:16 ---A- . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\clfs.sys [249784] O44 - LFC:[MD5.D824C1C235349B67E652A5CA70D1AA49] - 11-06-2015 - 18:36:16 ---A- . (.Microsoft Corporation - Common Log Marshalling Win32 DLL.) -- C:\Windows\System32\clfsw32.dll [58880] O44 - LFC:[MD5.5E714D8DE046CA462986E0DB79B027F8] - 11-06-2015 - 18:36:16 ---A- . (.Microsoft Corporation - Pilha de protocolo HTTP.) -- C:\Windows\System32\Drivers\http.sys [514560] O44 - LFC:[MD5.83EE20D7160484C9172FDF0ACBDC8929] - 11-06-2015 - 18:36:17 ---A- . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\Drivers\rdpvideominiport.sys [15872] O44 - LFC:[MD5.81D2D712EBB8CBB73AECB85D8835A168] - 11-06-2015 - 18:36:17 ---A- . (.Microsoft Corporation - UMRDP Display Driver.) -- C:\Windows\System32\rdpudd.dll [134656] O44 - LFC:[MD5.B36B3488D81E64D6026E838B8F087BAC] - 11-06-2015 - 18:36:18 ---A- . (.Microsoft Corporation - DLL RDPCore TS.) -- C:\Windows\System32\rdpcorets.dll [919552] O44 - LFC:[MD5.5F3628DCF926C4499BE1DC74431DFBC8] - 11-06-2015 - 18:36:19 ---A- . (.Microsoft Corporation - Microsoft Windows Codecs Library.) -- C:\Windows\System32\WindowsCodecs.dll [1230848] O44 - LFC:[MD5.BAF4974C26F4CD7689251BCB0859C553] - 11-06-2015 - 18:36:20 ---A- . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\System32\gdi32.dll [305152] O44 - LFC:[MD5.EC1C7DD0512A6588ACF3AAF297E2297D] - 11-06-2015 - 18:36:21 ---A- . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [176640] O44 - LFC:[MD5.DFD2AD666EBE2E8F8B2E46862B1201C5] - 11-06-2015 - 18:36:21 ---A- . (.Microsoft Corporation - User Profile WMI Provider.) -- C:\Windows\System32\profprov.dll [28672] O44 - LFC:[MD5.DA27A4EA7B7C77FAFDB3F94D83E310C1] - 11-06-2015 - 18:36:22 ---A- . (.Microsoft Corporation - Recursos do Windows Media Player.) -- C:\Windows\System32\wmploc.DLL [12625408] O44 - LFC:[MD5.2401379E0610D15FAB78A4B1646F5B8D] - 11-06-2015 - 18:36:23 ---A- . (.Microsoft Corporation - Microsoft Windows Media Component Removal F.) -- C:\Windows\System32\dxmasf.dll [4096] O44 - LFC:[MD5.2401379E0610D15FAB78A4B1646F5B8D] - 11-06-2015 - 18:36:23 ---A- . (.Microsoft Corporation - Microsoft Windows Media Component Removal F.) -- C:\Windows\System32\msdxm.ocx [4096] O44 - LFC:[MD5.605E9B2CFA3445ED7716D0B345EE21EC] - 11-06-2015 - 18:36:23 ---A- . (.Microsoft Corporation - Windows Media Player System Preparation DLL.) -- C:\Windows\System32\spwmp.dll [8192] O44 - LFC:[MD5.A98E8F79C738CAF23C152DBCABD978FE] - 11-06-2015 - 18:36:24 ---A- . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\System32\wmp.dll [11411456] O44 - LFC:[MD5.4D829D464A1CBBA195F8A5F911160E58] - 11-06-2015 - 18:36:27 ---A- . (.Microsoft Corporation - Controlador Win32 para vários utilizadores.) -- C:\Windows\System32\win32k.sys [2393088] O44 - LFC:[MD5.91A3AA2BCB2FBA1079B77C94FC1208F8] - 11-06-2015 - 18:36:28 ---A- . (.Microsoft Corporation - MSCTF Server DLL.) -- C:\Windows\System32\msctf.dll [829952] O44 - LFC:[MD5.955200436F29C751FEB30F139F0664B1] - 11-06-2015 - 18:36:30 ---A- . (.Microsoft Corporation - DLL do Monitor de Portas do Windows Journal.) -- C:\Windows\System32\jnwmon.dll [19968] O44 - LFC:[MD5.418AEC0CE89A13200F2820079B9CDFD9] - 11-06-2015 - 18:36:31 ---A- . (.Microsoft Corporation - Microsoft Tablet PC InkEdit Control.) -- C:\Windows\System32\InkEd.dll [216064] O44 - LFC:[MD5.C489D8B4D8C64F20CC75A93F541F7D91] - 11-06-2015 - 18:36:37 ---A- . (.Microsoft Corporation - Dispositivo de Execução de Filas de Operaçõ.) -- C:\Windows\System32\poqexec.exe [123904] O44 - LFC:[MD5.C22AB1781BC6F0BB1C9B352CF66DBFFC] - 11-06-2015 - 18:36:41 ---A- . (.Microsoft Corporation - Serviços Tipográficos DirectX da Microsoft.) -- C:\Windows\System32\DWrite.dll [1250816] O44 - LFC:[MD5.6EC244F102C7F129678E5F7309D1366D] - 11-06-2015 - 18:36:42 ---A- . (.Microsoft Corporation - Serviço de Cache de Tipos de Letra do Windo.) -- C:\Windows\System32\FntCache.dll [909312] O44 - LFC:[MD5.40D005C54EF08E3660C511B51AC2A560] - 11-06-2015 - 18:36:54 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408] O44 - LFC:[MD5.05F8F60BA4F0687CF44884CB02EA70ED] - 11-06-2015 - 18:36:54 ---A- . (.Microsoft Corporation - DLL de eventos de auditoria de segurança.) -- C:\Windows\System32\msaudite.dll [146432] O44 - LFC:[MD5.667E2779E260070A0EFE0E6EB63ABF97] - 11-06-2015 - 18:36:54 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872] O44 - LFC:[MD5.CDCCC1893A236FADD9DA0A2579F7E3E6] - 11-06-2015 - 18:36:54 ---A- . (.Microsoft Corporation - Nomes de auditoria dos objectos do sistema.) -- C:\Windows\System32\msobjs.dll [60416] O44 - LFC:[MD5.015BB331E9A7C2224624EFC672973A18] - 11-06-2015 - 18:36:54 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016] O44 - LFC:[MD5.CD1C453BF5A2DC9E82C6D58E9633A9FC] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Cliente de serviços de certificados de Micr.) -- C:\Windows\System32\certcli.dll [342528] O44 - LFC:[MD5.16E5771D435254189E9E2D02E69E774E] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520] O44 - LFC:[MD5.35F0817C803DFC520CBF7031B72B6A17] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528] O44 - LFC:[MD5.D8620BB81E6B8D0F861A59705CD902D6] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032] O44 - LFC:[MD5.73F6D19B52F5464093D981D850AC8555] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Programa de Políticas de Auditoria.) -- C:\Windows\System32\auditpol.exe [50176] O44 - LFC:[MD5.06926331ECA2D977FE5A95F6D5F7D7D9] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352] O44 - LFC:[MD5.4870081131A1F7001BAC38771E5F7152] - 11-06-2015 - 18:36:55 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536] O44 - LFC:[MD5.7B2EBE118A6D9A2C75C21B4B2CA156FA] - 11-06-2015 - 18:36:56 ---A- . (.Microsoft Corporation - Biblioteca criptográfica do Windows.) -- C:\Windows\System32\ncrypt.dll [221184] O44 - LFC:[MD5.7C78156AB00E870908DA85ECD66B2532] - 11-06-2015 - 18:36:56 ---A- . (.Microsoft Corporation - DLL do Esquema de Auditoria de Segurança.) -- C:\Windows\System32\adtschema.dll [690688] O44 - LFC:[MD5.94114114504921ACCC0289354D3B8A63] - 11-06-2015 - 18:36:56 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [137664] O44 - LFC:[MD5.564C7491FA6E89ECFB7BDB86CD5D913B] - 11-06-2015 - 18:36:56 ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [260096] O44 - LFC:[MD5.81E49397682C109EB2B0A9FE7838D89C] - 11-06-2015 - 18:36:56 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832] O44 - LFC:[MD5.6749D12B7375C1571554247490D84F9E] - 11-06-2015 - 18:36:57 ---A- . (.Microsoft Corporation - LSA Server DLL.) -- C:\Windows\System32\lsasrv.dll [1062912] O44 - LFC:[MD5.5480DAA9B7D24C18A4AB1E05D822AAE2] - 11-06-2015 - 18:36:57 ---A- . (.Microsoft Corporation - Pacote de segurança Kerberos.) -- C:\Windows\System32\kerberos.dll [551424] O44 - LFC:[MD5.422FA9F2DEBF3A36C7E49EC2DF0BEECA] - 11-06-2015 - 18:37:12 ---A- . (.Microsoft Corporation - ApiSet Schema DLL.) -- C:\Windows\System32\apisetschema.dll [6656] O44 - LFC:[MD5.8A2F7AB7A7FFA065FC621CE8FCC24D60] - 11-06-2015 - 18:37:13 ---A- . (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\Windows\System32\appidcertstorecheck.exe [16896] O44 - LFC:[MD5.FEC89B6173B546FE2C0AFDE487A50395] - 11-06-2015 - 18:37:13 ---A- . (.Microsoft Corporation - DLL de APIs de Identidade de Aplicação.) -- C:\Windows\System32\appidapi.dll [50688] O44 - LFC:[MD5.FA1F64E3939B7BCAAA0DB85FB49FBDBC] - 11-06-2015 - 18:37:13 ---A- . (.Microsoft Corporation - MUI Callback for Bcd.) -- C:\Windows\System32\setbcdlocale.dll [50176] O44 - LFC:[MD5.EC333DC212D11F1F5341F33B59854BA7] - 11-06-2015 - 18:37:13 ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Client Li.) -- C:\Windows\System32\srclient.dll [43008] O44 - LFC:[MD5.91442A511F69C5045CACE15648AB7F3C] - 11-06-2015 - 18:37:14 ---A- . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\Drivers\appid.sys [50688] O44 - LFC:[MD5.DE9B9656B51FE9A52471DD8A8B7EA365] - 11-06-2015 - 18:37:14 ---A- . (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\Windows\System32\appidpolicyconverter.exe [97792] O44 - LFC:[MD5.BCE230B8626E42E997285173A9426EE5] - 11-06-2015 - 18:37:14 ---A- . (.Microsoft Corporation - Gestor de Sessões do Windows.) -- C:\Windows\System32\smss.exe [69632] O44 - LFC:[MD5.4A4B70486192FAC0FF8D38D32A92D7E7] - 11-06-2015 - 18:37:14 ---A- . (.Microsoft Corporation - Processo de Tempo de Execução de Servidor C.) -- C:\Windows\System32\csrsrv.dll [38912] O44 - LFC:[MD5.A154A77056A773646653FA751210C4C3] - 11-06-2015 - 18:37:14 ---A- . (.Microsoft Corporation - Restauro do Sistema do Microsoft® Windows.) -- C:\Windows\System32\rstrui.exe [262656] O44 - LFC:[MD5.13B3D3851102C7D097DDA7449A9700F7] - 11-06-2015 - 18:37:14 ---A- . (.Microsoft Corporation - Serviço de Identidade de Aplicação.) -- C:\Windows\System32\appidsvc.dll [29696] O44 - LFC:[MD5.CD5D539B313F0EA2F5384AB10A590C7E] - 11-06-2015 - 18:37:15 ---A- . (.Microsoft Corporation - Biblioteca Principal do Restauro do Sistema.) -- C:\Windows\System32\srcore.dll [400896] O44 - LFC:[MD5.EC00AAC70120CEFC36A661BB2D4784FD] - 11-06-2015 - 18:37:16 ---A- . (.Microsoft Corporation - Aplicação de arranque para Sair do Modo de.) -- C:\Windows\System32\winresume.exe [458856] O44 - LFC:[MD5.1F693612FF5F19BED59CBB010C0D868E] - 11-06-2015 - 18:37:16 ---A- . (.Microsoft Corporation - DLL de camada do NT.) -- C:\Windows\System32\ntdll.dll [1306104] O44 - LFC:[MD5.52867720AC20A25102CC35A6AE3782AC] - 11-06-2015 - 18:37:16 ---A- . (.Microsoft Corporation - OS Loader.) -- C:\Windows\System32\winload.exe [523472] O44 - LFC:[MD5.D4E0D6FF3515292E0C79EBB36C5EB6BC] - 11-06-2015 - 18:37:18 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3981248] O44 - LFC:[MD5.B53EFFD5A376DB232A1A1D176636E451] - 11-06-2015 - 18:37:18 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3925944] O44 - LFC:[MD5.9D68CE45935C439D5082ECB56902124D] - 11-06-2015 - 18:37:33 ---A- . (.Microsoft Corporation - API Cliente de Windows Update.) -- C:\Windows\System32\wuapi.dll [566784] O44 - LFC:[MD5.124FD729FB2B621EB32E9B34B8D49A34] - 11-06-2015 - 18:37:33 ---A- . (.Microsoft Corporation - Windows Setup UI.) -- C:\Windows\System32\WinSetupUI.dll [50176] O44 - LFC:[MD5.7E5C454A3F986FEBAD075DB8D915917E] - 11-06-2015 - 18:37:33 ---A- . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2020864] O44 - LFC:[MD5.3096CA2455ECDEF83A90F2384BD305D3] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Experiência de Utilizador do Cliente de Win.) -- C:\Windows\System32\wucltux.dll [3088384] O44 - LFC:[MD5.751C4859FD46A1461B3FB57252F541D8] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update Application Launcher.) -- C:\Windows\System32\wuapp.exe [33792] O44 - LFC:[MD5.031C03C9639CE0D294695968C68A5775] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update Vista Web Control.) -- C:\Windows\System32\wuwebv.dll [173056] O44 - LFC:[MD5.E981C27FA6C2F45C135DB4AF78D6FE1F] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update WUDriver Stub.) -- C:\Windows\System32\wudriver.dll [92672] O44 - LFC:[MD5.0430D8CE2C251BAD25CF809CEA3D2153] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update client proxy stub 2.) -- C:\Windows\System32\wups2.dll [35328] O44 - LFC:[MD5.131BDD454DD1AA5BF732886DA6A3B0FA] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update client proxy stub for intern.) -- C:\Windows\System32\wu.upgrade.ps.dll [11776] O44 - LFC:[MD5.C7E498E41D92CF8C2EAED9995781A7F7] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update client proxy stub.) -- C:\Windows\System32\wups.dll [29696] O44 - LFC:[MD5.CFF96E0CE6F81F5968A6D61786642855] - 11-06-2015 - 18:37:34 ---A- . (.Microsoft Corporation - Windows Update.) -- C:\Windows\System32\wuauclt.exe [131584] O44 - LFC:[MD5.2CBD6D22499EB13A2666F62EF33D00E2] - 11-06-2015 - 18:37:53 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16303] O44 - LFC:[MD5.927E38A35E4DFC4E294BD130BAA6F759] - 11-06-2015 - 18:37:53 ---A- . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\System32\iertutil.dll [2278912] O44 - LFC:[MD5.975421AC32F9F6E27A58F75DAB4B5871] - 11-06-2015 - 18:37:54 ---A- . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [19607040] O44 - LFC:[MD5.3FD7E6DB5D81FE400DB4D81D278596E6] - 11-06-2015 - 18:37:56 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript9.dll [4305920] O44 - LFC:[MD5.9F6066005D8B8620598085C7499E9B70] - 11-06-2015 - 18:37:57 ---A- . (.Microsoft Corporation - DAC for Trident DOM.) -- C:\Windows\System32\MshtmlDac.dll [64000] O44 - LFC:[MD5.85E21CCF38166E0D6DE2E42D9D3823BD] - 11-06-2015 - 18:37:58 ---A- . (.Microsoft Corporation - Microsoft (R) HTML Media DLL.) -- C:\Windows\System32\mshtmlmedia.dll [1155072] O44 - LFC:[MD5.6B7210618D7E2CE0404ECF748701253A] - 11-06-2015 - 18:37:58 ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [76288] O44 - LFC:[MD5.EF853EA2A6A7BD891CCF31B0C2915352] - 11-06-2015 - 18:37:59 ---A- . (.Microsoft Corporation - Conversor de HTML da Microsoft.) -- C:\Windows\System32\html.iec [341504] O44 - LFC:[MD5.DB254D50B4527C2821C537E0587B44E8] - 11-06-2015 - 18:38:00 ---A- . (.Microsoft Corporation - Browser.) -- C:\Windows\System32\ieframe.dll [12829696] O44 - LFC:[MD5.1A628C1F5470F0AF21E37E425026F27A] - 11-06-2015 - 18:38:01 ---A- . (.Microsoft Corporation - Motor IU do Internet Explorer.) -- C:\Windows\System32\ieui.dll [478208] O44 - LFC:[MD5.E4EB138060BAE0DBAB1A3B71A3141FE7] - 11-06-2015 - 18:38:03 ---A- . (.Microsoft Corporation - Extensões da Internet para Win32.) -- C:\Windows\System32\wininet.dll [1950720] O44 - LFC:[MD5.AD392013A39DE951627EE402002E800C] - 11-06-2015 - 18:38:03 ---A- . (.Microsoft Corporation - IE ETW Collector Service Resources.) -- C:\Windows\System32\ieetwcollectorres.dll [4096] O44 - LFC:[MD5.C27C8CACEBC712BE2AD791715E9734EC] - 11-06-2015 - 18:38:03 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript.dll [664064] O44 - LFC:[MD5.FB5C9234E4BF6BDAF4A954763A4582BA] - 11-06-2015 - 18:38:04 ---A- . (.Microsoft Corporation - DLL de classificações da Internet e gestão.) -- C:\Windows\System32\msrating.dll [168960] O44 - LFC:[MD5.5C06EE62F06E990E9521EA80B8D4D4B8] - 11-06-2015 - 18:38:04 ---A- . (.Microsoft Corporation - Mapa de versão IOD.) -- C:\Windows\System32\iesetup.dll [62464] O44 - LFC:[MD5.4ABEEF30EA5B9F4718312DCB60B6C9BC] - 11-06-2015 - 18:38:04 ---A- . (.Microsoft Corporation - Opção Internet do Painel de Controlo.) -- C:\Windows\System32\inetcpl.cpl [2052608] O44 - LFC:[MD5.2DED8A99E45053C42DD21D6937D3960C] - 11-06-2015 - 18:38:06 ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [689152] O44 - LFC:[MD5.8C8B8C78C0CCD5D36ABCB115B0B581E1] - 11-06-2015 - 18:38:06 ---A- . (.Microsoft Corporation - Microsoft® MSHTML Typelib.) -- C:\Windows\System32\mshtml.tlb [2724864] O44 - LFC:[MD5.53E9614ADFA6A40A452BA014CEF6F261] - 11-06-2015 - 18:38:07 ---A- . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [1309696] O44 - LFC:[MD5.C93AE4D14AEF5169791B35D97AE7C9FC] - 11-06-2015 - 18:38:07 ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [47104] O44 - LFC:[MD5.B6D8148C1C697A7BF04EE0FE82408B6A] - 11-06-2015 - 18:38:07 ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter.) -- C:\Windows\System32\ieapfltr.dll [710144] O44 - LFC:[MD5.7DBCBB1647B7CD71E2039C1B50A12717] - 11-06-2015 - 18:38:07 ---A- . (.Microsoft Corporation - Microsoft ® JScript Diagnostics.) -- C:\Windows\System32\jscript9diag.dll [620032] O44 - LFC:[MD5.96837E5864777688477AF6DE2332C06D] - 11-06-2015 - 18:38:07 ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [503808] O44 - LFC:[MD5.E21AE910DF0C5CB7D46D8FA17A4567DE] - 11-06-2015 - 18:38:07 ---A- . (.Microsoft Corporation - Utilitário de Instalação Totalmente Silenci.) -- C:\Windows\System32\ieUnatt.exe [115712] O44 - LFC:[MD5.FA628D79E5FD267039A2F7637BA10754] - 11-06-2015 - 18:38:08 ---A- . (.Microsoft Corporation - Microsoft Spell Checking Facility.) -- C:\Windows\System32\MsSpellCheckingFacility.exe [667648] O44 - LFC:[MD5.81C1182A9EE7AC4D21187811DE66A7D0] - 11-06-2015 - 18:38:08 ---A- . (.Microsoft Corporation - Processamento RunOnce de extensão com UI.) -- C:\Windows\System32\iernonce.dll [30720] O44 - LFC:[MD5.ABE3B4B605499D726C27ACB6F756BC11] - 11-06-2015 - 18:38:08 ---A- . (.Microsoft Corporation - Utilitário de Inicialização por utilizador.) -- C:\Windows\System32\ie4uinit.exe [685568] O44 - LFC:[MD5.8C3A03295F56D1FFB51D9D05DA42B12D] - 11-06-2015 - 18:38:09 ---A- . (.Microsoft Corporation - IE ETW Collector Proxy Stub Resources.) -- C:\Windows\System32\ieetwproxystub.dll [47616] O44 - LFC:[MD5.C842601A18BA4D9058E7C0EFA5683513] - 11-06-2015 - 18:38:09 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [102912] O44 - LFC:[MD5.185490A6C3BEDAC5EF547314F68AB07B] - 11-06-2015 - 18:38:09 ---A- . (.Microsoft Corporation - JavaScript Performance Collection Agent.) -- C:\Windows\System32\JavaScriptCollectionAgent.dll [60416] O44 - LFC:[MD5.0780A42DBD7D9969F9BF4A19AA4285B5] - 11-06-2015 - 18:38:15 ---A- . (.Microsoft Corporation - Aplicação de serviços e controlo.) -- C:\Windows\System32\services.exe [259072] O44 - LFC:[MD5.63DD6A5798B5085BE2162D0A1A21589D] - 11-06-2015 - 18:38:16 ---A- . (.Microsoft Corporation - DLL do Gestor Unificado de Processos em Seg.) -- C:\Windows\System32\ubpm.dll [171520] O44 - LFC:[MD5.858EB73F68B20A2A5C66B6C000D1C0DD] - 11-06-2015 - 19:35:18 ---A- . (.Microsoft Corporation - WinFX OpenType/CFF Rasterizer.) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll [102608] O44 - LFC:[MD5.E185BDA84E5F03F4E1D8DCA30E209277] - 11-06-2015 - 19:40:56 ---A- . (...) -- C:\Windows\epplauncher.mif [1912] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 13-06-2015 - 13:27:39 ---A- . (...) -- C:\Windows\setuperr.log [0] O44 - LFC:[MD5.846EB652FD22639D150183D13974ADB9] - 13-06-2015 - 13:27:49 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [287888] O44 - LFC:[MD5.B922BE9C54575B95ACDE73AC5A8E1FFF] - 14-06-2015 - 12:58:31 ---A- . (...) -- C:\Windows\PFRO.log [360] O44 - LFC:[MD5.97E0710177157844A0B620267FACE1EB] - 14-06-2015 - 12:59:03 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.AC849B99E032F4017BB1CE37934DD4AF] - 14-06-2015 - 12:59:06 ---A- . (...) -- C:\Windows\setupact.log [112] O44 - LFC:[MD5.980925B2D7DB9558115828CC05BAAF68] - 14-06-2015 - 13:12:24 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1860789] O44 - LFC:[MD5.04B309A1A653177994630C2773E659F1] - 14-06-2015 - 18:21:11 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512] O44 - LFC:[MD5.3CEEBFAE7F720403E38AC42685878F6A] - 14-06-2015 - 18:50:25 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1654886] O44 - LFC:[MD5.035B997913581D68979C1077FC872024] - 14-06-2015 - 18:50:25 ---A- . (...) -- C:\Windows\System32\perfc009.dat [122012] O44 - LFC:[MD5.31CD8B2EF86D7E84CBD435CCB6AE9AB1] - 14-06-2015 - 18:50:25 ---A- . (...) -- C:\Windows\System32\perfh009.dat [654140] O44 - LFC:[MD5.AB14C1CEF798018154673BC3F7ABC328] - 14-06-2015 - 18:50:25 ---A- . (...) -- C:\Windows\System32\prfc0816.dat [152774] O44 - LFC:[MD5.620102EEC62A50C3001E69CF7AB105FA] - 14-06-2015 - 18:50:26 ---A- . (...) -- C:\Windows\System32\prfh0816.dat [720822] ~ Files: 204 Scanned in 01mn 11s ---\\ Exportar a chave da aplicação autorizada (047) O47 - AAKE:Key Export SP - "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe O47 - AAKE:Key Export SP - "C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe O47 - AAKE:Key Export SP - "C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe O47 - AAKE:Key Export SP - "C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe ~ Keys Export: 4 Scanned in 00mn 00s ---\\ Negação do serviço (Local Security Authority) (048) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Motor cliente do editor de configuração de protecção do Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pacote de segurança Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll ~ LSA: 8 Scanned in 00mn 00s ---\\ Controlo do Modo de Segurança (CSB) (49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Controlador de filtro de rato série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Controlador de Extensão do Gestor de Volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Controlador de filtro de rato série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Controlador de Extensão do Gestor de Volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn 00s ---\\ Chave do registo Shell MountPoints2 (MPSK) (O51) O51 - MPSK:{7f8f65be-0f47-11e4-a0c8-0016d4d0def7}\AutoRun\command. (...) -- E:\autorun.exe (.not file.) ~ Keys: Scanned in 00mn 00s ---\\ Pesquisa de infeções nos drivers (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ TDSD: 3 Scanned in 00mn 00s ---\\ Enumeração das chaves do registo SecurityProviders (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Enumeração das chaves do registo PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Scanned in 00mn 00s ---\\ Lista dos drivers do sistema (SDL) (O58) O58 - SDL:14-07-2009 - 01:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:14-07-2009 - 01:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552] O58 - SDL:14-07-2009 - 01:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512] O58 - SDL:14-07-2009 - 01:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400] O58 - SDL:26-05-2013 - 21:13:07 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256] O58 - SDL:14-07-2009 - 01:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312] O58 - SDL:26-05-2013 - 21:13:07 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400] O58 - SDL:18-10-2010 - 06:24:14 ---A- . (.Google Inc - ADB Interface.) -- C:\Windows\System32\Drivers\androidusb.sys [32408] O58 - SDL:14-07-2009 - 01:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368] O58 - SDL:14-07-2009 - 01:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608] O58 - SDL:13-07-2009 - 22:02:46 ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- C:\Windows\System32\Drivers\athr.sys [1096704] O58 - SDL:11-02-2010 - 07:42:22 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\Drivers\atikmdag.sys [4450816] O58 - SDL:13-07-2009 - 22:02:49 ---A- . (.Broadcom Corporation - Controlador Unificado Broadcom NetXtreme Gigabit Ethernet NDIS6.) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888] O58 - SDL:13-07-2009 - 22:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568] O58 - SDL:13-07-2009 - 22:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248] O58 - SDL:14-07-2009 - 00:57:25 ---A- . (.Brother Industries Ltd. - Controlador Série Brother I/F(WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128] O58 - SDL:13-07-2009 - 22:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336] O58 - SDL:13-07-2009 - 22:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160] O58 - SDL:13-07-2009 - 22:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904] O58 - SDL:13-07-2009 - 22:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080] O58 - SDL:14-07-2009 - 01:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952] O58 - SDL:14-07-2009 - 01:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720] O58 - SDL:14-07-2009 - 01:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712] O58 - SDL:01-12-2004 - 15:12:10 ---A- . (.ENE Technology Inc. - ENE PCI Memory Card Reader Driver.) -- C:\Windows\System32\Drivers\EMCR7SK.sys [105088] O58 - SDL:16-02-2006 - 09:55:12 ---A- . (.ENE Technology Inc. - ENE PCI Memory Stick Card Reader Driver.) -- C:\Windows\System32\Drivers\EMS7SK.sys [60928] O58 - SDL:25-10-2006 - 13:36:48 ---A- . (.ENE Technology Inc. - ENE PCI Secure Digital / MMC Card Reader Driver.) -- C:\Windows\System32\Drivers\ESD7SK.sys [42240] O58 - SDL:16-02-2006 - 09:55:16 ---A- . (.ENE Technology Inc. - ENE PCI SmartMedia / XD Card Reader Driver.) -- C:\Windows\System32\Drivers\ESM7SK.sys [74624] O58 - SDL:13-07-2009 - 22:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160] O58 - SDL:21-08-2012 - 13:01:22 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840] O58 - SDL:13-07-2009 - 22:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624] O58 - SDL:14-07-2009 - 01:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152] O58 - SDL:26-05-2013 - 21:13:07 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160] O58 - SDL:14-07-2009 - 01:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040] O58 - SDL:14-07-2009 - 01:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824] O58 - SDL:14-07-2009 - 01:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168] O58 - SDL:14-07-2009 - 01:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864] O58 - SDL:14-07-2009 - 01:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848] O58 - SDL:14-04-2015 - 08:37:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256] O58 - SDL:14-04-2015 - 08:37:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888] O58 - SDL:14-06-2015 - 18:21:11 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512] O58 - SDL:14-07-2009 - 01:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800] O58 - SDL:14-07-2009 - 01:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584] O58 - SDL:14-04-2015 - 08:37:54 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928] O58 - SDL:14-07-2009 - 01:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624] O58 - SDL:26-05-2013 - 21:13:07 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120] O58 - SDL:26-05-2013 - 21:13:07 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744] O58 - SDL:14-07-2009 - 01:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488] O58 - SDL:14-07-2009 - 01:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064] O58 - SDL:13-07-2009 - 22:02:52 ---A- . (.Realtek Semiconductor Corporation - Realtek 10/100 NDIS 5.1 Driver.) -- C:\Windows\System32\Drivers\Rtnicxp.sys [43008] O58 - SDL:13-07-2009 - 20:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480] O58 - SDL:13-07-2009 - 23:45:33 ---A- . (.Brother Industries Ltd. - Controlador Série Brother I/F(WDM).) -- C:\Windows\System32\Drivers\serial.sys [83456] O58 - SDL:14-07-2009 - 01:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016] O58 - SDL:14-07-2009 - 01:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888] O58 - SDL:01-01-1601 - 00:00:00 ---A- . (...) -- C:\Windows\System32\Drivers\sptd.sys [691696] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.Google Inc - ADB Interface.) -- C:\Windows\System32\Drivers\ssadadb.sys [30312] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - SAMSUNG Android USB Composite Device Driver.) -- C:\Windows\System32\Drivers\ssadbus.sys [121064] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadcm.sys [10472] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadcmnt.sys [10472] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - SAMSUNG Android USB Modem Filter Driver.) -- C:\Windows\System32\Drivers\ssadmdfl.sys [12776] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - SAMSUNG Android USB Modem.) -- C:\Windows\System32\Drivers\ssadmdm.sys [136808] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - SAMSUNG Android USB Diagnostic Serial Port Device Driver.) -- C:\Windows\System32\Drivers\ssadserd.sys [114280] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadwh.sys [10344] O58 - SDL:31-01-2013 - 08:19:34 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadwhnt.sys [10344] O58 - SDL:22-01-2014 - 08:52:12 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [88576] O58 - SDL:22-01-2014 - 08:52:12 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [184192] O58 - SDL:14-07-2009 - 01:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072] O58 - SDL:23-10-2006 - 10:17:32 ---A- . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [179896] O58 - SDL:15-08-2014 - 23:35:00 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl.sys [45056] O58 - SDL:14-07-2009 - 01:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976] O58 - SDL:14-07-2009 - 01:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904] O58 - SDL:13-07-2009 - 22:13:45 ---A- . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\Drivers\VSTAZL3.SYS [207360] O58 - SDL:13-07-2009 - 22:13:45 ---A- . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\Drivers\VSTCNXT3.SYS [661504] O58 - SDL:13-07-2009 - 22:13:46 ---A- . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\Drivers\VSTDPV3.SYS [980992] O58 - SDL:13-01-2011 - 03:17:18 ---A- . (.ZTE Inc. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\zghsmdm.sys [106752] O58 - SDL:13-07-2009 - 21:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:13-07-2009 - 21:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:03-04-1996 - 19:33:26 ---A- . (...) -- C:\Windows\System32\giveio.sys [5248] O58 - SDL:13-07-2009 - 21:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:13-07-2009 - 21:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:13-07-2009 - 21:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:13-07-2009 - 21:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:13-07-2009 - 21:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:13-07-2009 - 21:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:13-07-2009 - 21:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:13-07-2009 - 21:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:13-07-2009 - 21:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:13-07-2009 - 21:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:13-07-2009 - 21:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:13-07-2009 - 21:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:13-07-2009 - 21:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672] O58 - SDL:30-09-2013 - 15:26:46 ----- . (...) -- C:\Windows\System32\pwdrvio.sys [15688] O58 - SDL:30-09-2013 - 15:26:44 ----- . (...) -- C:\Windows\System32\pwdspio.sys [10320] O58 - SDL:29-12-2012 - 20:59:38 ---A- . (.Almico Software - SpeedFan x32 Driver.) -- C:\Windows\System32\speedfan.sys [24184] ~ Drivers: 93 Scanned in 00mn 06s ---\\ Últimos ficheiros alterados ou criados (Utilizador) (061) O61 - LFC: 13-06-2015 - 19:52:50 ---A- . (.Trend Micro Inc..) -- C:\Users\João\Downloads\HijackThis.exe [388608] O61 - LFC: 14-06-2015 - 19:52:13 ---A- . (...) -- C:\Users\João\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849] O61 - LFC: 14-06-2015 - 19:52:48 ---A- . (.Igor Pavlov.) -- C:\Users\João\AppData\Roaming\Maxthon3\Temp\MxUp\7z.dll [679296] O61 - LFC: 14-06-2015 - 19:52:50 ---A- . (.Nicolas Coolman.) -- C:\Users\João\Downloads\ZHPDiag2.exe [6880102] =>.Nicolas Coolman ~ 528 Fichiers temporaires (Temporary files) ~ 4 Fichiers cookies (Cookies files) ~ Files: 4 Scanned in 00mn 38s ---\\ Ficheiros Alternate Data Stream (ADS) (O62) O62 - ADS:Alternate Data Stream File - C:\Windows\System32\SynCOM.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\SynCtrl.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\SynTPAPI.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\SynTPCo4.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\WdfCoInstaller01000.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\Drivers\ESD7SK.sys:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\Drivers\SynTP.sys:Zone.Identifier ~ ADS: Scanned in 00mn 01s ---\\ Lista das ferramentas de remoção de vírus (LAT) (063) O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Lista dos serviços Legacy du registo (064) O64 - Services: CurCS - 13-07-2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 26-02-1746 - C:\Windows\System32\Drivers\sptd.sys (sptd) .(...) - LEGACY_SPTD ~ Legacy: 72 Scanned in 00mn 00s ---\\ Associações Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do Snap-in Visualizador de Eventos.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Editor de registo.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Scanned in 00mn 00s ---\\ Menu de inicialização Internet (068) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files\Maxthon\Bin\Maxthon.exe ~ Keys: Scanned in 00mn 00s ---\\ Pesquisa de infeção nos navegadores da Internet (SBI) (069) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Listagem dos serviços iniciados pelo Svchost (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Serviço Experiência de Aplicação.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificados de Smart Card da Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificados de Smart Card da Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL do Serviço de Servidor.) -- C:\Windows\System32\srvsvc.dll [167936] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente de Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [600064] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\ikeext.dll [681472] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Serviço de Áudio do Windows.) -- C:\Windows\System32\Audiosrv.dll [475136] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestor de Marcação Automática de Acesso Remoto.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestor de Ligação de Acesso Remoto.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestor de Interfaces Dinâmicas.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistema (SENS).) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\Windows\System32\ipnathlp.dll [300032] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestor de Ligações Remotas do Servidor de Anfitrião de Sessões de Ambi.) -- C:\Windows\System32\termsrv.dll [526848] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2020864] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente em segundo plano.) -- C:\Windows\System32\qmgr.dll [586240] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços da shell do Windows.) -- C:\Windows\System32\shsvcs.dll [329216] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 numa rede IPv4..) -- C:\Windows\System32\iphlpsvc.dll [502272] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL secundária de serviço de início de sessão.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações sobre Aplicações.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Detecção iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Serviço do Programador de Classes de Multimédia.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios e Soluções de Problemas.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço EAPHost da Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [176640] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Programador de Tarefas.) -- C:\Windows\System32\schedsvc.dll [751104] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração do Ambiente de Trabalho Remoto.) -- C:\Windows\System32\sessenv.dll [118272] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL do Browser de Computador.) -- C:\Windows\System32\browser.dll [102912] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL de Serviços de Tema da Shell do Windows.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [76800] O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação de software.) -- C:\Windows\System32\appmgmts.dll [149504] ~ Services: 33 Scanned in 00mn 00s ---\\ Pesquisa adicional à raiz do sistema (radicular) (SPRF) (O84) [MD5.BDF1532ED8619A685AF37EFED2912430] [SPRF][10-10-2014] (...) -- C:\Users\João\Desktop\Pangu_v1.2.1.exe [35796928] ~ Files: 1 Scanned in 00mn 02s ---\\ Lista das exceções do FireWall (FirewallRules) (O87) O87 - FAEL: "{5F8258E9-09B7-4DBC-92BE-E8D2FDE8ADC0}" | In - None - P6 - TRUE | .(.BitTorrent Inc. - BitTorrent.) -- C:\Users\João\AppData\Roaming\BitTorrent\BitTorrent.exe =>P2P.BitTorrent O87 - FAEL: "{7489E8B9-9D27-48C4-B5BB-FFE2CE002FDE}" | In - None - P17 - TRUE | .(.BitTorrent Inc. - BitTorrent.) -- C:\Users\João\AppData\Roaming\BitTorrent\BitTorrent.exe =>P2P.BitTorrent ~ Firewall: 2 Scanned in 00mn 02s ---\\ Search Tracing Registry Key (O100) HKLM\SOFTWARE\Microsoft\Tracing\BitTorrent_RASAPI32 =>P2P.BitTorrent HKLM\SOFTWARE\Microsoft\Tracing\BitTorrent_RASMANCS =>P2P.BitTorrent ~ BTK: 56 Scanned in 00mn 00s ---\\ Estado general dos serviços não Microsoft (EGS) (SR=Executados, SS=Parados) SS - | Demand 23-04-2015 713736 | (Garmin Device Interaction Service) . (.Garmin Ltd. or its subsidiaries.) - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe SS - | Auto 27-04-2015 107848 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 27-04-2015 107848 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Auto 14-04-2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe SS - | Auto 14-04-2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe SS - | Demand 13-06-2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 10-10-2014 1771560 | (PDF Architect 2) . (.pdfforge GmbH.) - C:\Program Files\PDF Architect 2\ws.exe SS - | Demand 10-10-2014 861736 | (pdfforge CrashHandler) . (.pdfforge GmbH.) - C:\Program Files\PDF Architect 2\crash-handler-ws.exe SS - | Auto 24-06-2014 1738168 | (SDScannerService) . (.Safer-Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe SS - | Demand 26-05-2013 21504 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 19-12-2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 19-01-2015 60744 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 11-02-2010 733184 | (Ati External Event Utility) . (.ATI Technologies Inc..) - C:\Windows\System32\Ati2evxx.exe SR - | Auto 30-08-2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Demand 27-01-2015 540968 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SR - | Auto 11-05-2015 1872152 | (MaxthonUpdateSvc) . (.Maxthon.) - C:\Program Files\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe SR - | Auto 30-04-2015 22216 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe SR - | Auto 27-06-2014 2088408 | (SDUpdateService) . (.Safer-Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe SR - | Auto 25-04-2014 171928 | (SDWSCService) . (.Safer-Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe SR - | Auto 26-05-2013 21504 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 01mn 00s ---\\ Pesquisa de infeção no Registo Mestre de Inicialização (MBR) (080) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net ~ MBR: 1 Scanned in 00mn 03s ---\\ Pesquisa de infeção no Registo Mestre de Inicialização (MBRCheck) (080) Written by ad13, http://ad13.geekstog Run by João at 14-06-2015 19:55:09 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 05s ---\\ Lista dos emuladores de CD/DVD (MBR Hook) O58 - SDL:01-01-1601 - 00:00:00 ---A- . (...) -- C:\Windows\System32\Drivers\sptd.sys [691696] ~ Emulateurs: Scanned in 00mn 05s ---\\ Scâner Aditional (088) Database Version : 13008 - (31-05-2015) Clés trouvées (Keys found) : 1 Valeurs trouvées (Values found) : 1 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent] =>P2P.BitTorrent^ C:\Users\João\AppData\Roaming\BitTorrent =>P2P.BitTorrent^ ~ Additionnel Scan: 236787 Items scanned in 00mn 39s ---\\ Informações complémentaires do módulos ~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Arranque,Pesquisa,Extensões (G0,G1,G2) ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Gestão do Proxy (R5) ~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects do navegador (02) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Aplicações iniciadas por registo & pastas (04) ~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Chave do registo Shell MountPoints2 (MPSK) (O51) ~ AMI: 5 Scanned in 00mn 00s End of the scan (1326 lines in 05mn 01s)(0.6)