Logo Hardware.com.br
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas

[Resolvido] Acesso Negado

#1 Por R. Moran 13/01/2021 - 12:34
Boa tarde. Há alguns dias o antivírus (Bitdefender) detectou uma ameaça em meu notebook. Foi para quarentena e de lá deletei o arquivo infectado. Porém algum tempo depois novamente o mesmo vírus foi reportado. Novamente deletei mas ele continuou aparecendo. Até que me deparei com outro problema. Ao tentar montar uma imagem ISO tive a permissão negada. Tentei várias abordagens para tentar resolver e nada. Uma delas foi tentar fazer uma cópia da imagem, mas ao solicitar permissão do ADM para realizar também tive a permissão negada. Na pasta TEMP o arquivo mencionado apresenta assim: "SppExtComObjHook.dll.166753.gzquar". Creio que ambos os eventos estejam relacionados, por isso usei a ferramenta ZHPDiag e em seguida a ZHPCleaner, fiz o scam, cliquei em Repair e gerou o relatório abaixo:

~ ZHPCleaner v2021.1.12.268 by Nicolas Coolman (2021/01/12)
~ Run by Ramon (Administrator) (13/01/2021 12:01:31)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 18362)


---\\ Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\ Services (0)
~ No malicious or unnecessary items found.


---\\ Browser internet (0)
~ No malicious or unnecessary items found.


---\\ Hosts file (1)
~ The hosts file is legitimate (15669)


---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\ Explorer ( File, Folder) (6)
MOVED file: C:\end =>SUP.Optional.Conduit
MOVED file: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 - AutoKMS] =>HackTool.AutoKMS
MOVED file: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS
MOVED folder: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
MOVED folder: C:\WINDOWS\AutoKMS =>HackTool.AutoKMS
MOVED folder: C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update =>Heuristic.Suspect


---\\ Registry ( Key, Value, Data) (4)
DELETED key*: [X64] HKLM\SOFTWARE\DtsEncodeTools [] =>PUP.Optional.WeatherTool
DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player NPAPI Notifier [] =>Riskware.FlashPlayer
DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater [] =>Riskware.FlashPlayer
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI [Adobe Systems Incorporated] =>Riskware.FlashPlayer


---\\ Summary of the elements found (5)
https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>SUP.Optional.Conduit
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>PUP.Optional.WeatherTool
https://nicolascoolman.eu/forum/Topic/flashplayer-logiciel-a-risque-riskware/ =>Riskware.FlashPlayer


---\\ Other deletions. (15)
~ Registry Keys Tracing deleted (15)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Google Chrome OK
~ Internet Explorer OK
~ The system has been restarted.


---\\ Statistics
~ Items scanned : 32437
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/16


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis





~ End of clean in 00h01mn30s

---\\ Reports (2)
ZHPCleaner-[S]-13012021-11_54_03.txt
ZHPCleaner-[R]-13012021-12_03_01.txt[/S]
[S]

Meu note é um ACER Aspire E15, Core I3, com Windows 10 Pro 64-bit. Agradeço a atenção e aguardo instruções sobre como eliminar esse problema. Abs[/s]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#2 Por joram
13/01/2021 - 14:08
/!\ Boa Tarde! R.Moran /!\

Imagem
http://www.hardware.com.br/comunidade/v-t/1226830/

Siga as recomendações oficiais deste Tópico e poste: FRST.txt + Addition.txt

Imagem << ( ... by Farbar )

Ps: É fundamental que a FRST.exe,seja baixada ao desktop! (Área de trabalho)

Imagem

Disponibilize os relatórios em Cjoint.com ou utilize spoiler,cuja instrução está ao final daquela página.

[]s
PH
PH Cyber Highlander Registrado
61.4K Mensagens 10.7K Curtidas
#3 Por PH
13/01/2021 - 14:32
R. Moran disse:
Boa tarde. Há alguns dias o antivírus (Bitdefender) detectou uma ameaça em meu notebook. Foi para quarentena e de lá deletei o arquivo infectado. Porém algum tempo depois novamente o mesmo vírus foi reportado. Novamente deletei mas ele continuou aparecendo. Até que me deparei com outro problema. Ao tentar montar uma imagem ISO tive a permissão negada. Tentei várias abordagens para tentar resolver e nada. Uma delas foi tentar fazer uma cópia da imagem, mas ao solicitar permissão do ADM para realizar também tive a permissão negada. Na pasta TEMP o arquivo mencionado apresenta assim: "SppExtComObjHook.dll.166753.gzquar". Creio que ambos os eventos estejam relacionados, por isso usei a ferramenta ZHPDiag e em seguida a ZHPCleaner, fiz o scam, cliquei em Repair e gerou o relatório abaixo:

~ ZHPCleaner v2021.1.12.268 by Nicolas Coolman (2021/01/12)
~ Run by Ramon (Administrator) (13/01/2021 12:01:31)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 18362)


---\\ Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\ Services (0)
~ No malicious or unnecessary items found.


---\\ Browser internet (0)
~ No malicious or unnecessary items found.


---\\ Hosts file (1)
~ The hosts file is legitimate (15669)


---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\ Explorer ( File, Folder) (6)
MOVED file: C:\end =>SUP.Optional.Conduit
MOVED file: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 - AutoKMS] =>HackTool.AutoKMS
MOVED file: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS
MOVED folder: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
MOVED folder: C:\WINDOWS\AutoKMS =>HackTool.AutoKMS
MOVED folder: C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update =>Heuristic.Suspect


---\\ Registry ( Key, Value, Data) (4)
DELETED key*: [X64] HKLM\SOFTWARE\DtsEncodeTools [] =>PUP.Optional.WeatherTool
DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player NPAPI Notifier [] =>Riskware.FlashPlayer
DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater [] =>Riskware.FlashPlayer
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI [Adobe Systems Incorporated] =>Riskware.FlashPlayer


---\\ Summary of the elements found (5)
https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>SUP.Optional.Conduit
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>PUP.Optional.WeatherTool
https://nicolascoolman.eu/forum/Topic/flashplayer-logiciel-a-risque-riskware/ =>Riskware.FlashPlayer


---\\ Other deletions. (15)
~ Registry Keys Tracing deleted (15)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Google Chrome OK
~ Internet Explorer OK
~ The system has been restarted.


---\\ Statistics
~ Items scanned : 32437
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/16


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis





~ End of clean in 00h01mn30s

---\\ Reports (2)
ZHPCleaner-[S]-13012021-11_54_03.txt
ZHPCleaner-[R]-13012021-12_03_01.txt[/S]

[S]
Meu note é um ACER Aspire E15, Core I3, com Windows 10 Pro 64-bit. Agradeço a atenção e aguardo instruções sobre como eliminar esse problema. Abs[/S]


Boa tarde!

Você usa o Windows ou Office pirata? Tem mais algum programa ou jogo no seu computador que seja pirata?
Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas
#4 Por R. Moran
13/01/2021 - 20:07
Segue conforme solicitado:

https://www.cjoint.com/c/KAnw7Xh8Ssr
https://www.cjoint.com/c/KAnxdphIrBr

PH disse:
Boa tarde!

Você usa o Windows ou Office pirata? Tem mais algum programa ou jogo no seu computador que seja pirata?

Não, não são piratas. Faz uns quatro anos fazia parte de uma empresa e compramos um pacote do Windows 10 + Office. A empresa não existe mais, fechou ano passado. E recentemente a chave de ativação para uso comercial (que não é mais o caso) expirou. Não renovei, mas utilizo esse note agora apenas para lazer e aprendizado. Tanto que não prejudica em nada o funcionamento ou atualizaçoes, que continuam ocorrendo normalmente.
R. Moran
"Podemos facilmente perdoar uma criança que tem medo do escuro; a real tragédia da vida é quando os homens têm medo da luz."
Platão
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#5 Por joram
13/01/2021 - 21:37
/!\ Boa Noite! R. Moran /!\

> Desinstale: Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)

> Copie estas informações que estão no Spoiler,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite!
> Salve-as ao desktop! ( Área de trabalho ... )

Imagem
"fixlist"
start::
CloseProcesses:
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
HKLM\...\RunOnce: [ZHPCleaner] => C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPCleaner.txt [3241 2021-01-13] () [Arquivo não assinado]
HKLM-x32\...\RunOnce: [ZHPCleaner_Key1] => REG delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player NPAPI Notifier" /F /reg:64
HKLM-x32\...\RunOnce: [ZHPCleaner_Key2] => REG delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" /F /reg:64
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\...\MountPoints2: {2efb81ec-d163-11e8-b13b-5cc9d35961df} - "E:\setup.exe"
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\...\MountPoints2: {b002cd2b-1ba4-11ea-b14c-1c394752449d} - "F:\setup.exe"
BootExecute: autocheck autochk * bddel.exe
Policies: C:\ProgramData\NTUSER.pol: Restrição <==== ATENÇÃO
Policies: C:\Users\Todos os Usuários\NTUSER.pol: Restrição <==== ATENÇÃO
Task: {42CB79C9-4DE6-4D53-93C2-353715BC8551} - \Microsoft\Windows\UNP\RunCampaignManager -> Nenhum Arquivo <==== ATENÇÃO
Task: {50ECE5A8-FD99-476F-B1C5-CB81EA720D85} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe
Task: {DFF93D81-35D1-4E30-BF0D-8BA0207C3CA1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {EC93523F-A203-486D-A2CC-7E8FAF04B7A6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [4747720 2014-06-27] (Safer Networking Ltd. -> Safer-Networking Ltd.)
Task: {EF2B4C49-26C1-465A-B4D5-6BD2C1CDE63E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [5753752 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
Task: {F61DBD50-E9AA-4663-92A3-ADE236DF7F36} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [6193080 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
Edge StartupUrls: Default -> "hxxp://www.fidonav.com/"
Edge DefaultSearchURL: Default -> hxxps://br.search.yahoo.com/search{googlestick_out_tongue.pngathWildcard}?ei={inputEncoding}&fr=crmas&p={searchTerms}
Edge DefaultSearchKeyword: Default -> br.yahoo.com
Edge DefaultSuggestURL: Default -> hxxps://br.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
FF Plugin HKU\S-1-5-21-2109982156-1193874355-445741488-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [Nenhum Arquivo]
FF Plugin HKU\S-1-5-21-2109982156-1193874355-445741488-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [Nenhum Arquivo]
CHR HomePage: Default -> hxxp://maisdowns.com
CHR StartupUrls: Default -> "hxxps://www.google.com.br/","hxxps://www.google.com.br/","hxxp:www.fidonav.com"
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 MBAMSwissArmy; \SystemRoot\System32\Drivers\mbamswissarmy.sys [X]
2021-01-13 12:03 - 2021-01-13 12:03 - 000010233 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).html
2021-01-13 12:03 - 2021-01-13 12:03 - 000003241 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).txt
2021-01-13 11:54 - 2021-01-13 11:54 - 000010015 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).html
2021-01-13 11:54 - 2021-01-13 11:54 - 000003108 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).txt
2021-01-13 11:38 - 2021-01-13 11:38 - 000000884 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner.lnk
2021-01-13 11:28 - 2021-01-13 11:29 - 003341960 _____ (Nicolas Coolman) C:\Users\Ramon.NOTEBOOK\Downloads\ZHPCleaner.exe
2021-01-13 10:05 - 2019-11-28 22:20 - 000003808 _____ C:\WINDOWS\system32\Tasks\AutoKMS
CustomCLSID: HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Nenhum Arquivo
ContextMenuHandlers1: [axcrypt.File] -> [CC]{C3DFC144-30F8-4138-81F9-578DBEB9324A} => -> Nenhum Arquivo
ContextMenuHandlers1: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> Nenhum Arquivo
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> Nenhum Arquivo
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> [CC]{C06369D6-E77D-4626-9656-1256312BD576} => -> Nenhum Arquivo
ContextMenuHandlers3: [DaemonShellExtImageLite] -> [CC]{1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => -> Nenhum Arquivo
ContextMenuHandlers4: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> Nenhum Arquivo
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Nenhum Arquivo
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES000&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
StartPowershell:
DISM /Online /Cleanup-image /Restorehealth
sfc /scannow
EndPowershell:
CreateRestorePoint:
SystemRestore: On
EmptyTemp:
Reboot:
Hosts:
end::


Imagem

> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool". (Fixlog.txt)
> Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs

< Este script foi elaborado exclusivamente para este computador,portanto peço aos visitantes que não o utilize em outras "máquinas". >

[]s
PH
PH Cyber Highlander Registrado
61.4K Mensagens 10.7K Curtidas
#6 Por PH
14/01/2021 - 09:12
R. Moran disse:
Não, não são piratas. Faz uns quatro anos fazia parte de uma empresa e compramos um pacote do Windows 10 + Office. A empresa não existe mais, fechou ano passado. E recentemente a chave de ativação para uso comercial (que não é mais o caso) expirou. Não renovei, mas utilizo esse note agora apenas para lazer e aprendizado. Tanto que não prejudica em nada o funcionamento ou atualizaçoes, que continuam ocorrendo normalmente.


Bom dia!

Eu lhe pergunto por causa disso.

MOVED file: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 - AutoKMS] =>HackTool.AutoKMS
MOVED file: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS
MOVED folder: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
MOVED folder: C:\WINDOWS\AutoKMS =>HackTool.AutoKMS


Esse AutoKMS é usado para ativação ilegal do Windows e Office.

Dessa forma, pode usar todos os procedimentos para deixar o computador limpe e rápido, mas se continuar usando esses tipos de programas para burlar a ativação do sistema, os problemas sempre voltarão.
Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas
#7 Por R. Moran
14/01/2021 - 20:50
joram disse:
/!\ Boa Noite! R. Moran /!\

> Desinstale: Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)

> Copie estas informações que estão no Spoiler,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite!
> Salve-as ao desktop! ( Área de trabalho ... )

Imagem
"fixlist"
start::
CloseProcesses:
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
HKLM\...\RunOnce: [ZHPCleaner] => C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPCleaner.txt [3241 2021-01-13] () [Arquivo não assinado]
HKLM-x32\...\RunOnce: [ZHPCleaner_Key1] => REG delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player NPAPI Notifier" /F /reg:64
HKLM-x32\...\RunOnce: [ZHPCleaner_Key2] => REG delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" /F /reg:64
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\...\MountPoints2: {2efb81ec-d163-11e8-b13b-5cc9d35961df} - "E:\setup.exe"
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\...\MountPoints2: {b002cd2b-1ba4-11ea-b14c-1c394752449d} - "F:\setup.exe"
BootExecute: autocheck autochk * bddel.exe
Policies: C:\ProgramData\NTUSER.pol: Restrição <==== ATENÇÃO
Policies: C:\Users\Todos os Usuários\NTUSER.pol: Restrição <==== ATENÇÃO
Task: {42CB79C9-4DE6-4D53-93C2-353715BC8551} - \Microsoft\Windows\UNP\RunCampaignManager -> Nenhum Arquivo <==== ATENÇÃO
Task: {50ECE5A8-FD99-476F-B1C5-CB81EA720D85} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe
Task: {DFF93D81-35D1-4E30-BF0D-8BA0207C3CA1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {EC93523F-A203-486D-A2CC-7E8FAF04B7A6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [4747720 2014-06-27] (Safer Networking Ltd. -> Safer-Networking Ltd.)
Task: {EF2B4C49-26C1-465A-B4D5-6BD2C1CDE63E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [5753752 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
Task: {F61DBD50-E9AA-4663-92A3-ADE236DF7F36} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [6193080 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
Edge StartupUrls: Default -> "hxxp://www.fidonav.com/"
Edge DefaultSearchURL: Default -> hxxps://br.search.yahoo.com/search{googlestick_out_tongue.pngathWildcard}?ei={inputEncoding}&fr=crmas&p={searchTerms}
Edge DefaultSearchKeyword: Default -> br.yahoo.com
Edge DefaultSuggestURL: Default -> hxxps://br.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
FF Plugin HKU\S-1-5-21-2109982156-1193874355-445741488-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [Nenhum Arquivo]
FF Plugin HKU\S-1-5-21-2109982156-1193874355-445741488-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [Nenhum Arquivo]
CHR HomePage: Default -> hxxp://maisdowns.com
CHR StartupUrls: Default -> "hxxps://www.google.com.br/","hxxps://www.google.com.br/","hxxp:www.fidonav.com"
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 MBAMSwissArmy; \SystemRoot\System32\Drivers\mbamswissarmy.sys [X]
2021-01-13 12:03 - 2021-01-13 12:03 - 000010233 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).html
2021-01-13 12:03 - 2021-01-13 12:03 - 000003241 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).txt
2021-01-13 11:54 - 2021-01-13 11:54 - 000010015 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).html
2021-01-13 11:54 - 2021-01-13 11:54 - 000003108 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).txt
2021-01-13 11:38 - 2021-01-13 11:38 - 000000884 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner.lnk
2021-01-13 11:28 - 2021-01-13 11:29 - 003341960 _____ (Nicolas Coolman) C:\Users\Ramon.NOTEBOOK\Downloads\ZHPCleaner.exe
2021-01-13 10:05 - 2019-11-28 22:20 - 000003808 _____ C:\WINDOWS\system32\Tasks\AutoKMS
CustomCLSID: HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Nenhum Arquivo
ContextMenuHandlers1: [axcrypt.File] -> [CC]{C3DFC144-30F8-4138-81F9-578DBEB9324A} => -> Nenhum Arquivo
ContextMenuHandlers1: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> Nenhum Arquivo
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> Nenhum Arquivo
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> [CC]{C06369D6-E77D-4626-9656-1256312BD576} => -> Nenhum Arquivo
ContextMenuHandlers3: [DaemonShellExtImageLite] -> [CC]{1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => -> Nenhum Arquivo
ContextMenuHandlers4: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> Nenhum Arquivo
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Nenhum Arquivo
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES000&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
StartPowershell:
DISM /Online /Cleanup-image /Restorehealth
sfc /scannow
EndPowershell:
CreateRestorePoint:
SystemRestore: On
EmptyTemp:
Reboot:
Hosts:
end::


Imagem

> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool". (Fixlog.txt)
> Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs

< Este script foi elaborado exclusivamente para este computador,portanto peço aos visitantes que não o utilize em outras "máquinas". >

[]s


Segue abaixo resultado da correção:


Resultado da Correção pela Farbar Recovery Scan Tool (x64) Versão: 09-01-2021
Executado por Ramon (14-01-2021 19:04:33) Run:1
Executando a partir de C:\Users\Ramon.NOTEBOOK\Desktop
Perfis Carregados: Ramon
Modo da Inicialização: Normal
==============================================

fixlist Conteúdo:
*****************
CloseProcesses:
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
HKLM\...\RunOnce: [ZHPCleaner] => C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPCleaner.txt [3241 2021-01-13] () [Arquivo não assinado]
HKLM-x32\...\RunOnce: [ZHPCleaner_Key1] => REG delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player NPAPI Notifier" /F /reg:64
HKLM-x32\...\RunOnce: [ZHPCleaner_Key2] => REG delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" /F /reg:64
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\...\MountPoints2: {2efb81ec-d163-11e8-b13b-5cc9d35961df} - "E:\setup.exe"
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\...\MountPoints2: {b002cd2b-1ba4-11ea-b14c-1c394752449d} - "F:\setup.exe"
BootExecute: autocheck autochk * bddel.exe
Policies: C:\ProgramData\NTUSER.pol: Restrição <==== ATENÇÃO
Policies: C:\Users\Todos os Usuários\NTUSER.pol: Restrição <==== ATENÇÃO
Task: {42CB79C9-4DE6-4D53-93C2-353715BC8551} - \Microsoft\Windows\UNP\RunCampaignManager -> Nenhum Arquivo <==== ATENÇÃO
Task: {50ECE5A8-FD99-476F-B1C5-CB81EA720D85} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe
Task: {DFF93D81-35D1-4E30-BF0D-8BA0207C3CA1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {EC93523F-A203-486D-A2CC-7E8FAF04B7A6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [4747720 2014-06-27] (Safer Networking Ltd. -> Safer-Networking Ltd.)
Task: {EF2B4C49-26C1-465A-B4D5-6BD2C1CDE63E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [5753752 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
Task: {F61DBD50-E9AA-4663-92A3-ADE236DF7F36} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [6193080 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
Edge StartupUrls: Default -> "hxxp://www.fidonav.com/"
Edge DefaultSearchURL: Default -> hxxps://br.search.yahoo.com/search{googlestick_out_tongue.pngathWildcard}?ei={inputEncoding}&fr=crmas&p={searchTerms}
Edge DefaultSearchKeyword: Default -> br.yahoo.com
Edge DefaultSuggestURL: Default -> hxxps://br.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
FF Plugin HKU\S-1-5-21-2109982156-1193874355-445741488-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [Nenhum Arquivo]
FF Plugin HKU\S-1-5-21-2109982156-1193874355-445741488-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [Nenhum Arquivo]
CHR HomePage: Default -> hxxp://maisdowns.com
CHR StartupUrls: Default -> "hxxps://www.google.com.br/","hxxps://www.google.com.br/","hxxp:www.fidonav.com"
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Arquivo não assinado]
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 MBAMSwissArmy; \SystemRoot\System32\Drivers\mbamswissarmy.sys [X]
2021-01-13 12:03 - 2021-01-13 12:03 - 000010233 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).html
2021-01-13 12:03 - 2021-01-13 12:03 - 000003241 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).txt
2021-01-13 11:54 - 2021-01-13 11:54 - 000010015 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).html
2021-01-13 11:54 - 2021-01-13 11:54 - 000003108 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).txt
2021-01-13 11:38 - 2021-01-13 11:38 - 000000884 _____ C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner.lnk
2021-01-13 11:28 - 2021-01-13 11:29 - 003341960 _____ (Nicolas Coolman) C:\Users\Ramon.NOTEBOOK\Downloads\ZHPCleaner.exe
2021-01-13 10:05 - 2019-11-28 22:20 - 000003808 _____ C:\WINDOWS\system32\Tasks\AutoKMS
CustomCLSID: HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Nenhum Arquivo
ContextMenuHandlers1: [axcrypt.File] -> [CC]{C3DFC144-30F8-4138-81F9-578DBEB9324A} => -> Nenhum Arquivo
ContextMenuHandlers1: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> Nenhum Arquivo
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> Nenhum Arquivo
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> [CC]{C06369D6-E77D-4626-9656-1256312BD576} => -> Nenhum Arquivo
ContextMenuHandlers3: [DaemonShellExtImageLite] -> [CC]{1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => -> Nenhum Arquivo
ContextMenuHandlers4: [DropboxExt] -> [CC]{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> Nenhum Arquivo
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Nenhum Arquivo
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES000&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-2109982156-1193874355-445741488-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
StartPowershell:
DISM /Online /Cleanup-image /Restorehealth
sfc /scannow
EndPowershell:
CreateRestorePoint:
SystemRestore: On
EmptyTemp:
Reboot:
Hosts:

*****************

Processos fechados com sucesso.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SDTray" => não encontrado (a)
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ZHPCleaner" => não encontrado (a)
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\ZHPCleaner_Key1" => não encontrado (a)
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\ZHPCleaner_Key2" => não encontrado (a)
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2efb81ec-d163-11e8-b13b-5cc9d35961df} => removido (a) com sucesso.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b002cd2b-1ba4-11ea-b14c-1c394752449d} => removido (a) com sucesso.
HKLM\System\CurrentControlSet\Control\Session Manager\\"BootExecute"="autocheck autochk *" => valor restaurado com sucesso
C:\ProgramData\NTUSER.pol => movido com sucesso
"C:\Users\Todos os Usuários\NTUSER.pol" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{42CB79C9-4DE6-4D53-93C2-353715BC8551}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{42CB79C9-4DE6-4D53-93C2-353715BC8551}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{50ECE5A8-FD99-476F-B1C5-CB81EA720D85}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50ECE5A8-FD99-476F-B1C5-CB81EA720D85}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\AutoKMS => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DFF93D81-35D1-4E30-BF0D-8BA0207C3CA1}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFF93D81-35D1-4E30-BF0D-8BA0207C3CA1}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC93523F-A203-486D-A2CC-7E8FAF04B7A6}" => não encontrado (a)
"C:\WINDOWS\System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking\Spybot - Search and Destroy\Check for updates" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF2B4C49-26C1-465A-B4D5-6BD2C1CDE63E}" => não encontrado (a)
"C:\WINDOWS\System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F61DBD50-E9AA-4663-92A3-ADE236DF7F36}" => não encontrado (a)
"C:\WINDOWS\System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking\Spybot - Search and Destroy\Scan the system" => não encontrado (a)
"Edge StartupUrls" => removido (a) com sucesso.
"Edge DefaultSearchURL" => removido (a) com sucesso.
"Edge DefaultSearchKeyword" => removido (a) com sucesso.
"Edge DefaultSuggestURL" => removido (a) com sucesso.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\MozillaPlugins\@tools.google.com/Google Update;version=3 => removido (a) com sucesso.
"C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll" => não encontrado (a)
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\MozillaPlugins\@tools.google.com/Google Update;version=9 => removido (a) com sucesso.
"C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll" => não encontrado (a)
"Chrome HomePage" => removido (a) com sucesso.
"Chrome StartupUrls" => removido (a) com sucesso.
SDScannerService => serviço não encontrado (a).
SDUpdateService => serviço não encontrado (a).
SDWSCService => serviço não encontrado (a).
HKLM\System\CurrentControlSet\Services\MBAMChameleon => removido (a) com sucesso.
MBAMChameleon => serviço removido (a) com sucesso.
HKLM\System\CurrentControlSet\Services\MBAMSwissArmy => removido (a) com sucesso.
MBAMSwissArmy => serviço removido (a) com sucesso.
C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).html => movido com sucesso
C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (R).txt => movido com sucesso
C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).html => movido com sucesso
C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner (S).txt => movido com sucesso
C:\Users\Ramon.NOTEBOOK\Desktop\ZHPCleaner.lnk => movido com sucesso
C:\Users\Ramon.NOTEBOOK\Downloads\ZHPCleaner.exe => movido com sucesso
"C:\WINDOWS\system32\Tasks\AutoKMS" => não encontrado (a)
HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F} => não encontrado (a)
HKU\S-1-5-21-2109982156-1193874355-445741488-1002_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4} => não encontrado (a)
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\axcrypt.File => removido (a) com sucesso.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\DropboxExt => removido (a) com sucesso.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\SDECon32 => não encontrado (a)
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\SDECon64 => não encontrado (a)
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UAContextMenu => removido (a) com sucesso.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR => removido (a) com sucesso.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 => removido (a) com sucesso.
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\DaemonShellExtDriveLite => removido (a) com sucesso.
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\DaemonShellExtImageLite => removido (a) com sucesso.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\DropboxExt => removido (a) com sucesso.
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removido (a) com sucesso.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\SDECon32 => não encontrado (a)
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\SDECon64 => não encontrado (a)
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UAContextMenu => removido (a) com sucesso.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" => valor restaurado com sucesso
"HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removido (a) com sucesso.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removido (a) com sucesso.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => removido (a) com sucesso.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" => não encontrado (a)
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" => não encontrado (a)
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" => não encontrado (a)
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" => não encontrado (a)

========= Powershell: =========


Ferramenta de Gerenciamento e Manutenção de Imagens de Implantação
Versão: 10.0.18362.900

Versão da Imagem: 10.0.18362.900


[== 4.5% ]

[== 4.5% ]

[== 4.5% ]

[== 4.5% ]

[== 4.6% ]

[== 4.6% ]

[== 4.6% ]

[== 4.6% ]

[== 4.7% ]

[== 4.7% ]

[== 4.8% ]

[== 4.8% ]

[== 4.8% ]

[== 4.9% ]

[== 4.9% ]

[== 4.9% ]

[== 4.9% ]

[== 5.0% ]

[== 5.0% ]

[== 5.0% ]

[== 5.1% ]

[== 5.1% ]

[=== 5.2% ]

[=== 5.2% ]

[=== 5.2% ]

[=== 5.2% ]

[=== 5.3% ]

[=== 5.3% ]

[=== 5.3% ]

[=== 5.4% ]

[=== 5.4% ]

[=== 5.4% ]

[=== 5.5% ]

[=== 5.5% ]

[=== 5.5% ]

[=== 5.5% ]

[=== 5.6% ]

[=== 5.6% ]

[=== 5.7% ]

[=== 5.7% ]

[=== 5.8% ]

[=== 5.8% ]

[=== 5.9% ]

[=== 5.9% ]

[=== 6.0% ]

[=== 6.0% ]

[=== 6.1% ]

[=== 6.2% ]

[=== 6.3% ]

[=== 6.3% ]

[=== 6.4% ]

[=== 6.4% ]

[=== 6.5% ]

[=== 6.5% ]

[=== 6.5% ]

[=== 6.5% ]

[=== 6.6% ]

[=== 6.6% ]

[=== 6.7% ]

[=== 6.7% ]

[=== 6.7% ]

[=== 6.8% ]

[=== 6.8% ]

[==== 6.9% ]

[==== 7.0% ]

[==== 7.1% ]

[==== 7.2% ]

[==== 7.3% ]

[==== 7.3% ]

[==== 7.4% ]

[==== 7.4% ]

[==== 7.5% ]

[==== 7.5% ]

[==== 7.5% ]

[==== 7.5% ]

[==== 7.5% ]

[==== 7.6% ]

[==== 7.6% ]

[==== 7.7% ]

[==== 7.7% ]

[==== 7.8% ]

[==== 7.9% ]

[==== 7.9% ]

[==== 8.0% ]

[==== 8.0% ]

[==== 8.0% ]

[==== 8.1% ]

[==== 8.1% ]

[==== 8.2% ]

[==== 8.2% ]

[==== 8.2% ]

[==== 8.2% ]

[==== 8.2% ]

[==== 8.3% ]

[==== 8.3% ]

[==== 8.3% ]

[==== 8.4% ]

[==== 8.4% ]

[==== 8.4% ]

[==== 8.4% ]

[==== 8.4% ]

[==== 8.4% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[==== 8.5% ]

[===== 8.6% ]

[===== 8.6% ]

[===== 8.7% ]

[===== 8.7% ]

[===== 8.7% ]

[===== 8.8% ]

[===== 8.8% ]

[===== 8.9% ]

[===== 8.9% ]

[===== 9.0% ]

[===== 9.0% ]

[===== 9.1% ]

[===== 9.1% ]

[===== 9.2% ]

[===== 9.2% ]

[===== 9.3% ]

[===== 9.3% ]

[===== 9.4% ]

[===== 9.5% ]

[===== 9.5% ]

[===== 9.5% ]

[===== 9.6% ]

[===== 9.8% ]

[===== 9.8% ]

[===== 9.8% ]

[===== 9.9% ]

[===== 10.0% ]

[===== 10.1% ]

[===== 10.2% ]

[===== 10.3% ]

[====== 10.4% ]

[====== 10.5% ]

[====== 10.5% ]

[====== 10.6% ]

[====== 10.7% ]

[====== 10.8% ]

[====== 11.0% ]

[====== 11.0% ]

[====== 11.2% ]

[====== 11.4% ]

[====== 11.6% ]

[====== 11.7% ]

[====== 11.8% ]

[====== 11.8% ]

[======= 12.5% ]

[======= 12.5% ]

[======= 12.5% ]

[======= 12.6% ]

[======= 12.6% ]

[======= 12.7% ]

[======= 12.7% ]

[======= 12.8% ]

[======= 12.8% ]

[======= 13.0% ]

[======= 13.0% ]

[======= 13.1% ]

[======= 13.2% ]

[======= 13.2% ]

[======= 13.3% ]

[======= 13.4% ]

[======= 13.4% ]

[======= 13.5% ]

[======= 13.5% ]

[======= 13.5% ]

[======= 13.5% ]

[======= 13.7% ]

[======== 13.8% ]

[======== 13.8% ]

[======== 13.9% ]

[======== 13.9% ]

[======== 14.0% ]

[======== 14.1% ]

[======== 14.2% ]

[======== 14.2% ]

[======== 14.3% ]

[======== 14.4% ]

[======== 14.4% ]

[======== 14.4% ]

[======== 14.4% ]

[======== 14.5% ]

[======== 14.5% ]

[======== 14.5% ]

[======== 14.5% ]

[======== 14.5% ]

[======== 14.5% ]

[======== 14.6% ]

[======== 14.6% ]

[======== 14.7% ]

[======== 14.7% ]

[======== 14.7% ]

[======== 14.8% ]

[======== 14.8% ]

[======== 14.8% ]

[======== 14.8% ]

[======== 14.9% ]

[======== 14.9% ]

[======== 14.9% ]

[======== 14.9% ]

[======== 15.0% ]

[======== 15.0% ]

[======== 15.0% ]

[======== 15.1% ]

[======== 15.1% ]

[======== 15.2% ]

[======== 15.2% ]

[======== 15.2% ]

[======== 15.3% ]

[======== 15.3% ]

[======== 15.4% ]

[======== 15.5% ]

[======== 15.5% ]

[========= 15.5% ]

[========= 15.6% ]

[========= 15.6% ]

[========= 15.7% ]

[========= 15.8% ]

[========= 15.9% ]

[========= 16.0% ]

[========= 16.0% ]

[========= 16.1% ]

[========= 16.2% ]

[========= 16.3% ]

[========= 16.4% ]

[========= 16.5% ]

[========= 16.5% ]

[========= 16.5% ]

[========= 16.6% ]

[========= 16.6% ]

[========= 16.7% ]

[========= 16.8% ]

[========= 16.9% ]

[========= 16.9% ]

[========= 17.1% ]

[========= 17.1% ]

[========= 17.2% ]

[========== 17.3% ]

[========== 17.4% ]

[========== 17.5% ]

[========== 17.5% ]

[========== 17.6% ]

[========== 17.7% ]

[========== 17.7% ]

[========== 17.8% ]

[========== 17.8% ]

[========== 17.9% ]

[========== 17.9% ]

[========== 17.9% ]

[========== 18.0% ]

[========== 18.1% ]

[========== 18.2% ]

[========== 18.3% ]

[========== 18.4% ]

[========== 18.5% ]

[========== 18.5% ]

[========== 18.6% ]

[========== 18.7% ]

[========== 18.8% ]

[========== 18.9% ]

[========== 18.9% ]

[========== 18.9% ]

[=========== 19.0% ]

[=========== 19.1% ]

[=========== 19.2% ]

[=========== 19.2% ]

[=========== 19.3% ]

[=========== 19.4% ]

[=========== 19.5% ]

[=========== 19.5% ]

[=========== 19.5% ]

[=========== 19.6% ]

[=========== 19.7% ]

[=========== 19.7% ]

[=========== 19.7% ]

[=========== 19.9% ]

[=========== 20.0% ]

[=========== 20.0% ]

[=========== 20.1% ]

[=========== 20.2% ]

[=========== 20.3% ]

[=========== 20.4% ]

[=========== 20.4% ]

[=========== 20.5% ]

[=========== 20.5% ]

[=========== 20.6% ]

[=========== 20.6% ]

[============ 20.7% ]

[============ 20.8% ]

[============ 20.8% ]

[============ 20.9% ]

[============ 21.0% ]

[============ 21.1% ]

[============ 21.1% ]

[============ 21.2% ]

[============ 21.3% ]

[============ 21.4% ]

[============ 21.5% ]

[============ 21.5% ]

[============ 21.6% ]

[============ 21.6% ]

[============ 21.7% ]

[============ 21.8% ]

[============ 21.9% ]

[============ 21.9% ]

[============ 22.0% ]

[============ 22.1% ]

[============ 22.1% ]

[============ 22.2% ]

[============ 22.3% ]

[============ 22.4% ]

[============= 22.5% ]

[============= 22.5% ]

[============= 22.5% ]

[============= 22.5% ]

[============= 22.5% ]

[============= 22.5% ]

[============= 22.5% ]

[============= 22.6% ]

[============= 22.6% ]

[============= 22.7% ]

[============= 22.8% ]

[============= 22.8% ]

[============= 22.8% ]

[============= 22.9% ]

[============= 22.9% ]

[============= 23.0% ]

[============= 23.0% ]

[============= 23.1% ]

[============= 23.1% ]

[============= 23.2% ]

[============= 23.2% ]

[============= 23.3% ]

[============= 23.3% ]

[============= 23.3% ]

[============= 23.3% ]

[============= 23.4% ]

[============= 23.5% ]

[============= 23.5% ]

[============= 23.6% ]

[============= 23.7% ]

[============= 23.8% ]

[============= 23.8% ]

[============= 23.8% ]

[============= 23.8% ]

[============= 23.8% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 23.9% ]

[============= 24.0% ]

[============= 24.0% ]

[============= 24.0% ]

[============= 24.1% ]

[============= 24.1% ]

[============= 24.1% ]

[============== 24.2% ]

[============== 24.2% ]

[============== 24.3% ]

[============== 24.8% ]

[============== 24.9% ]

[============== 25.0% ]

[============== 25.6% ]

[=============== 26.6% ]

[=============== 26.8% ]

[=============== 27.4% ]

[=============== 27.4% ]

[================ 28.0% ]

[================ 28.5% ]

[================ 28.9% ]

[================= 29.5% ]

[================= 29.5% ]

[================= 30.5% ]

[================== 31.2% ]

[================== 32.2% ]

[================== 32.7% ]

[=================== 33.5% ]

[=================== 33.5% ]

[=================== 33.6% ]

[=================== 33.6% ]

[=================== 33.6% ]

[=================== 33.7% ]

[=================== 33.8% ]

[=================== 33.8% ]

[=================== 33.9% ]

[=================== 34.0% ]

[=================== 34.1% ]

[=================== 34.1% ]

[=================== 34.2% ]

[=================== 34.2% ]

[=================== 34.2% ]

[=================== 34.5% ]

[==================== 34.7% ]

[==================== 34.7% ]

[==================== 34.8% ]

[==================== 34.8% ]

[==================== 34.8% ]

[==================== 34.9% ]

[==================== 34.9% ]

[==================== 35.0% ]

[==================== 35.0% ]

[==================== 35.1% ]

[==================== 35.1% ]

[==================== 35.2% ]

[==================== 35.2% ]

[==================== 35.3% ]

[==================== 35.3% ]

[==================== 35.3% ]

[==================== 35.3% ]

[==================== 35.4% ]

[==================== 35.4% ]

[==================== 35.5% ]

[==================== 35.5% ]

[==================== 35.5% ]

[==================== 35.7% ]

[==================== 36.1% ]

[===================== 36.3% ]

[===================== 36.4% ]

[===================== 36.7% ]

[===================== 36.8% ]

[===================== 36.9% ]

[===================== 37.1% ]

[===================== 37.5% ]

[===================== 37.5% ]

[===================== 37.6% ]

[===================== 37.7% ]

[===================== 37.8% ]

[===================== 37.9% ]

[====================== 38.0% ]

[====================== 38.1% ]

[====================== 38.2% ]

[====================== 38.3% ]

[====================== 38.4% ]

[====================== 38.5% ]

[====================== 38.5% ]

[====================== 38.8% ]

[====================== 39.3% ]

[====================== 39.5% ]

[======================= 39.8% ]

[======================= 40.3% ]

[======================= 40.5% ]

[======================= 40.5% ]

[======================= 40.5% ]

[======================= 40.8% ]

[======================= 41.1% ]

[======================== 41.5% ]

[======================== 41.8% ]

[======================== 41.9% ]

[======================== 42.0% ]

[======================== 42.3% ]

[======================== 42.5% ]

[======================== 42.8% ]

[======================== 43.0% ]

[======================== 43.0% ]

[========================= 43.5% ]

[========================= 43.5% ]

[========================= 43.6% ]

[========================= 43.8% ]

[========================= 43.8% ]

[========================= 44.2% ]

[========================= 44.4% ]

[========================= 44.6% ]

[========================= 44.7% ]

[========================= 44.8% ]

[========================= 44.8% ]

[========================== 44.9% ]

[========================== 45.0% ]

[========================== 45.1% ]

[========================== 45.1% ]

[========================== 45.3% ]

[========================== 45.4% ]

[========================== 45.4% ]

[========================== 45.5% ]

[========================== 45.5% ]

[========================== 45.5% ]

[========================== 45.6% ]

[========================== 45.7% ]

[========================== 45.8% ]

[========================== 45.9% ]

[========================== 46.0% ]

[========================== 46.1% ]

[========================== 46.2% ]

[========================== 46.3% ]

[========================== 46.4% ]

[========================== 46.5% ]

[========================== 46.5% ]

[===========================46.6% ]

[===========================46.7% ]

[===========================46.8% ]

[===========================46.9% ]

[===========================47.0% ]

[===========================47.1% ]

[===========================47.2% ]

[===========================47.3% ]

[===========================47.9% ]

[===========================48.7% ]

[===========================49.2% ]

[===========================49.3% ]

[===========================49.3% ]

[===========================49.3% ]

[===========================49.4% ]

[===========================49.4% ]

[===========================49.5% ]

[===========================49.5% ]

[===========================49.5% ]

[===========================49.5% ]

[===========================49.6% ]

[===========================49.6% ]

[===========================49.7% ]

[===========================49.7% ]

[===========================49.8% ]

[===========================49.8% ]

[===========================49.9% ]

[===========================49.9% ]

[===========================49.9% ]

[===========================50.0% ]

[===========================50.0% ]

[===========================50.0% ]

[===========================50.0% ]

[===========================50.0% ]

[===========================50.1% ]

[===========================50.1% ]

[===========================50.1% ]

[===========================50.2% ]

[===========================50.2% ]

[===========================50.3% ]

[===========================50.3% ]

[===========================50.3% ]

[===========================50.4% ]

[===========================50.4% ]

[===========================50.4% ]

[===========================50.5% ]

[===========================50.5% ]

[===========================50.5% ]

[===========================50.5% ]

[===========================50.5% ]

[===========================50.6% ]

[===========================50.7% ]

[===========================50.8% ]

[===========================50.9% ]

[===========================51.0% ]

[===========================51.1% ]

[===========================51.3% ]

[===========================51.4% ]

[===========================51.5% ]

[===========================51.5% ]

[===========================51.5% ]

[===========================51.6% ]

[===========================51.6% ]

[===========================51.6% ]

[===========================51.7% ]

[===========================51.7% ]

[===========================51.7% ]

[===========================51.8% ]

[===========================51.8% ]

[===========================51.8% ]

[===========================51.9% ]

[===========================51.9% ]

[===========================51.9% ]

[===========================52.0% ]

[===========================52.0% ]

[===========================52.0% ]

[===========================52.0% ]

[===========================52.1% ]

[===========================52.1% ]

[===========================52.1% ]

[===========================52.2% ]

[===========================52.2% ]

[===========================52.2% ]

[===========================52.3% ]

[===========================52.3% ]

[===========================52.3% ]

[===========================52.4% ]

[===========================52.4% ]

[===========================52.4% ]

[===========================52.4% ]

[===========================52.4% ]

[===========================52.5% ]

[===========================52.5% ]

[===========================52.5% ]

[===========================52.5% ]

[===========================52.5% ]

[===========================52.5% ]

[===========================52.5% ]

[===========================52.6% ]

[===========================52.6% ]

[===========================52.7% ]

[===========================52.7% ]

[===========================52.8% ]

[===========================52.8% ]

[===========================52.9% ]

[===========================52.9% ]

[===========================52.9% ]

[===========================52.9% ]

[===========================53.0% ]

[===========================53.0% ]

[===========================53.0% ]

[===========================53.1% ]

[===========================53.1% ]

[===========================53.1% ]

[===========================53.2% ]

[===========================53.3% ]

[===========================53.3% ]

[===========================53.3% ]

[===========================53.4% ]

[===========================53.4% ]

[===========================53.5% ]

[===========================53.5% ]

[===========================53.6% ]

[===========================53.6% ]

[===========================53.7% ]

[===========================53.8% ]

[===========================53.9% ]

[===========================54.0% ]

[===========================54.1% ]

[===========================54.9% ]

[===========================54.9% ]

[===========================55.0% ]

[===========================55.0% ]

[===========================55.0% ]

[===========================55.1% ]

[===========================55.1% ]

[===========================55.1% ]

[===========================55.2% ]

[===========================55.2% ]

[===========================55.3% ]

[===========================55.3% ]

[===========================55.3% ]

[===========================55.4% ]

[===========================55.4% ]

[===========================55.4% ]

[===========================55.5% ]

[===========================55.5% ]

[===========================55.5% ]

[===========================55.5% ]

[===========================55.5% ]

[===========================55.5% ]

[===========================55.6% ]

[===========================55.7% ]

[===========================55.7% ]

[===========================55.8% ]

[===========================55.8% ]

[===========================55.9% ]

[===========================56.0% ]

[===========================56.0% ]

[===========================56.1% ]

[===========================56.2% ]

[===========================56.2% ]

[===========================56.3% ]

[===========================56.3% ]

[===========================56.4% ]

[===========================56.4% ]

[===========================56.5% ]

[===========================56.5% ]

[===========================56.5% ]

[===========================56.5% ]

[===========================56.6% ]

[===========================56.7% ]

[===========================56.8% ]

[===========================56.9%= ]

[===========================57.0%= ]

[===========================57.1%= ]

[===========================57.2%= ]

[===========================57.8%= ]

[===========================57.9%= ]

[===========================57.9%= ]

[===========================58.0%= ]

[===========================58.1%= ]

[===========================58.1%= ]

[===========================58.2%= ]

[===========================58.2%= ]

[===========================58.3%= ]

[===========================58.3%= ]

[===========================58.4%= ]

[===========================58.5%= ]

[===========================58.5%= ]

[===========================58.5%= ]

[===========================58.5%= ]

[===========================58.6%== ]

[===========================58.6%== ]

[===========================58.7%== ]

[===========================58.7%== ]

[===========================58.8%== ]

[===========================58.8%== ]

[===========================58.8%== ]

[===========================58.9%== ]

[===========================58.9%== ]

[===========================59.0%== ]

[===========================59.0%== ]

[===========================59.1%== ]

[===========================59.1%== ]

[===========================59.2%== ]

[===========================59.2%== ]

[===========================59.3%== ]

[===========================59.3%== ]

[===========================59.4%== ]

[===========================59.5%== ]

[===========================59.5%== ]

[===========================59.5%== ]

[===========================59.6%== ]

[===========================59.6%== ]

[===========================59.7%== ]

[===========================59.8%== ]

[===========================59.9%== ]

[===========================60.0%== ]

[===========================60.0%== ]

[===========================60.1%== ]

[===========================60.1%== ]

[===========================60.2%== ]

[===========================60.3%== ]

[===========================60.3%== ]

[===========================60.4%=== ]

[===========================60.4%=== ]

[===========================60.5%=== ]

[===========================60.5%=== ]

[===========================60.5%=== ]

[===========================60.6%=== ]

[===========================60.6%=== ]

[===========================60.7%=== ]

[===========================60.7%=== ]

[===========================60.8%=== ]

[===========================60.8%=== ]

[===========================60.9%=== ]

[===========================60.9%=== ]

[===========================61.1%=== ]

[===========================61.2%=== ]

[===========================61.3%=== ]

[===========================61.4%=== ]

[===========================61.5%=== ]

[===========================61.5%=== ]

[===========================61.7%=== ]

[===========================61.8%=== ]

[===========================61.9%=== ]

[===========================62.1%==== ]

[===========================62.1%==== ]

[===========================62.2%==== ]

[===========================62.3%==== ]

[===========================62.4%==== ]

[===========================62.5%==== ]

[===========================62.5%==== ]

[===========================62.6%==== ]

[===========================62.7%==== ]

[===========================62.9%==== ]

[===========================63.0%==== ]

[===========================63.0%==== ]

[===========================63.1%==== ]

[===========================63.2%==== ]

[===========================63.2%==== ]

[===========================63.4%==== ]

[===========================63.4%==== ]

[===========================63.5%==== ]

[===========================63.6%==== ]

[===========================63.8%===== ]

[===========================63.9%===== ]

[===========================64.0%===== ]

[===========================64.0%===== ]

[===========================64.1%===== ]

[===========================64.2%===== ]

[===========================64.2%===== ]

[===========================64.3%===== ]

[===========================64.5%===== ]

[===========================64.5%===== ]

[===========================64.6%===== ]

[===========================64.7%===== ]

[===========================64.9%===== ]

[===========================64.9%===== ]

[===========================65.1%===== ]

[===========================65.2%===== ]

[===========================65.3%===== ]

[===========================65.8%====== ]

[===========================66.3%====== ]

[===========================66.3%====== ]

[===========================66.4%====== ]

[===========================66.5%====== ]

[===========================66.5%====== ]

[===========================66.6%====== ]

[===========================66.7%====== ]

[===========================66.8%====== ]

[===========================67.0%====== ]

[===========================67.1%====== ]

[===========================67.2%====== ]

[===========================67.8%======= ]

[===========================68.2%======= ]

[===========================68.3%======= ]

[===========================68.5%======= ]

[===========================68.5%======= ]

[===========================68.6%======= ]

[===========================68.7%======= ]

[===========================68.8%======= ]

[===========================68.9%======= ]

[===========================69.0%======== ]

[===========================69.1%======== ]

[===========================69.9%======== ]

[===========================70.1%======== ]

[===========================70.2%======== ]

[===========================70.3%======== ]

[===========================70.5%======== ]

[===========================70.5%======== ]

[===========================70.7%========= ]

[===========================71.2%========= ]

[===========================71.2%========= ]

[===========================71.2%========= ]

[===========================71.3%========= ]

[===========================71.3%========= ]

[===========================71.3%========= ]

[===========================71.4%========= ]

[===========================71.5%========= ]

[===========================71.5%========= ]

[===========================71.5%========= ]

[===========================71.5%========= ]

[===========================71.5%========= ]

[===========================71.6%========= ]

[===========================71.6%========= ]

[===========================71.7%========= ]

[===========================71.7%========= ]

[===========================71.8%========= ]

[===========================71.8%========= ]

[===========================71.9%========= ]

[===========================71.9%========= ]

[===========================72.0%========= ]

[===========================72.0%========= ]

[===========================72.1%========= ]

[===========================72.1%========= ]

[===========================72.2%========= ]

[===========================72.2%========= ]

[===========================72.2%========= ]

[===========================72.3%========= ]

[===========================72.3%========= ]

[===========================72.3%========= ]

[===========================72.4%========= ]

[===========================72.5%========== ]

[===========================72.5%========== ]

[===========================72.5%========== ]

[===========================72.5%========== ]

[===========================72.6%========== ]

[===========================72.6%========== ]

[===========================72.7%========== ]

[===========================72.7%========== ]

[===========================72.8%========== ]

[===========================72.8%========== ]

[===========================72.9%========== ]

[===========================72.9%========== ]

[===========================72.9%========== ]

[===========================73.0%========== ]

[===========================73.0%========== ]

[===========================73.0%========== ]

[===========================73.1%========== ]

[===========================73.1%========== ]

[===========================73.2%========== ]

[===========================73.2%========== ]

[===========================73.3%========== ]

[===========================73.3%========== ]

[===========================73.4%========== ]

[===========================73.5%========== ]

[===========================73.5%========== ]

[===========================73.5%========== ]

[===========================73.5%========== ]

[===========================73.5%========== ]

[===========================73.6%========== ]

[===========================73.6%========== ]

[===========================73.7%========== ]

[===========================73.7%========== ]

[===========================73.7%========== ]

[===========================73.8%========== ]

[===========================73.8%========== ]

[===========================73.8%========== ]

[===========================73.9%========== ]

[===========================73.9%========== ]

[===========================73.9%========== ]

[===========================74.0%========== ]

[===========================74.1%========== ]

[===========================74.1%========== ]

[===========================74.1%========== ]

[===========================74.2%=========== ]

[===========================74.2%=========== ]

[===========================74.3%=========== ]

[===========================74.3%=========== ]

[===========================74.4%=========== ]

[===========================74.5%=========== ]

[===========================74.5%=========== ]

[===========================74.5%=========== ]

[===========================74.6%=========== ]

[===========================74.6%=========== ]

[===========================74.7%=========== ]

[===========================74.7%=========== ]

[===========================74.8%=========== ]

[===========================74.8%=========== ]

[===========================74.9%=========== ]

[===========================75.0%=========== ]

[===========================75.0%=========== ]

[===========================75.1%=========== ]

[===========================75.1%=========== ]

[===========================75.1%=========== ]

[===========================75.2%=========== ]

[===========================75.2%=========== ]

[===========================75.3%=========== ]

[===========================75.4%=========== ]

[===========================75.4%=========== ]

[===========================75.4%=========== ]

[===========================75.5%=========== ]

[===========================75.5%=========== ]

[===========================75.5%=========== ]

[===========================75.5%=========== ]

[===========================75.6%=========== ]

[===========================75.7%=========== ]

[===========================75.7%=========== ]

[===========================75.8%=========== ]

[===========================75.8%=========== ]

[===========================75.9%============ ]

[===========================76.0%============ ]

[===========================76.0%============ ]

[===========================76.0%============ ]

[===========================76.1%============ ]

[===========================76.2%============ ]

[===========================76.2%============ ]

[===========================76.2%============ ]

[===========================76.3%============ ]

[===========================76.4%============ ]

[===========================76.4%============ ]

[===========================76.5%============ ]

[===========================76.5%============ ]

[===========================76.5%============ ]

[===========================76.5%============ ]

[===========================76.6%============ ]

[===========================76.6%============ ]

[===========================76.7%============ ]

[===========================76.7%============ ]

[===========================76.7%============ ]

[===========================76.7%============ ]

[===========================76.8%============ ]

[===========================76.8%============ ]

[===========================76.8%============ ]

[===========================76.9%============ ]

[===========================76.9%============ ]

[===========================76.9%============ ]

[===========================77.0%============ ]

[===========================77.0%============ ]

[===========================77.0%============ ]

[===========================77.0%============ ]

[===========================77.1%============ ]

[===========================77.1%============ ]

[===========================77.1%============ ]

[===========================77.1%============ ]

[===========================77.2%============ ]

[===========================77.2%============ ]

[===========================77.2%============ ]

[===========================77.3%============ ]

[===========================77.3%============ ]

[===========================77.3%============ ]

[===========================77.3%============ ]

[===========================77.4%============ ]

[===========================77.4%============ ]

[===========================77.5%============ ]

[===========================77.5%============ ]

[===========================77.5%============ ]

[===========================77.5%============ ]

[===========================77.5%============ ]

[===========================77.6%============= ]

[===========================77.6%============= ]

[===========================77.6%============= ]

[===========================77.7%============= ]

[===========================77.8%============= ]

[===========================77.8%============= ]

[===========================77.9%============= ]

[===========================77.9%============= ]

[===========================77.9%============= ]

[===========================78.0%============= ]

[===========================78.0%============= ]

[===========================78.1%============= ]

[===========================78.1%============= ]

[===========================78.2%============= ]

[===========================78.3%============= ]

[===========================78.3%============= ]

[===========================78.3%============= ]

[===========================78.4%============= ]

[===========================78.4%============= ]

[===========================78.5%============= ]

[===========================78.5%============= ]

[===========================78.6%============= ]

[===========================78.7%============= ]

[===========================78.7%============= ]

[===========================78.8%============= ]

[===========================78.8%============= ]

[===========================78.8%============= ]

[===========================78.9%============= ]

[===========================79.0%============= ]

[===========================79.0%============= ]

[===========================79.1%============= ]

[===========================79.1%============= ]

[===========================79.1%============= ]

[===========================79.2%============= ]

[===========================79.2%============= ]

[===========================79.3%============= ]

[===========================79.4%============== ]

[===========================79.5%============== ]

[===========================79.5%============== ]

[===========================79.5%============== ]

[===========================79.6%============== ]

[===========================79.6%============== ]

[===========================79.7%============== ]

[===========================79.8%============== ]

[===========================79.8%============== ]

[===========================79.9%============== ]

[===========================79.9%============== ]

[===========================80.0%============== ]

[===========================80.1%============== ]

[===========================80.2%============== ]

[===========================80.3%============== ]

[===========================80.4%============== ]

[===========================80.4%============== ]

[===========================80.5%============== ]

[===========================80.5%============== ]

[===========================80.5%============== ]

[===========================80.6%============== ]

[===========================80.7%============== ]

[===========================80.8%============== ]

[===========================80.9%============== ]

[===========================81.0%============== ]

[===========================81.0%============== ]

[===========================81.1%=============== ]

[===========================81.1%=============== ]

[===========================81.3%=============== ]

[===========================81.4%=============== ]

[===========================81.4%=============== ]

[===========================81.5%=============== ]

[===========================81.5%=============== ]

[===========================81.5%=============== ]

[===========================81.6%=============== ]

[===========================81.6%=============== ]

[===========================81.8%=============== ]

[===========================82.0%=============== ]

[===========================82.1%=============== ]

[===========================82.3%=============== ]

[===========================82.5%=============== ]

[===========================82.6%=============== ]

[===========================82.8%================ ]

[===========================82.9%================ ]

[===========================83.1%================ ]

[===========================83.3%================ ]

[===========================83.4%================ ]

[===========================83.6%================ ]

[===========================83.8%================ ]

[===========================84.1%================ ]

[===========================84.9%================= ]

[===========================84.9%================= ]

[===========================85.0%================= ]

[===========================85.0%================= ]

[===========================85.1%================= ]

[===========================85.1%================= ]

[===========================85.2%================= ]

[===========================85.3%================= ]

[===========================85.4%================= ]

[===========================85.5%================= ]

[===========================85.5%================= ]

[===========================85.6%================= ]

[===========================85.6%================= ]

[===========================85.7%================= ]

[===========================85.8%================= ]

[===========================85.8%================= ]

[===========================85.9%================= ]

[===========================85.9%================= ]

[===========================85.9%================= ]

[===========================86.0%================= ]

[===========================86.1%================= ]

[===========================86.1%================= ]

[===========================87.1%================== ]

[===========================87.7%================== ]

[===========================87.8%================== ]

[===========================87.9%================== ]

[===========================88.0%=================== ]

[===========================88.0%=================== ]

[===========================88.1%=================== ]

[===========================88.2%=================== ]

[===========================88.3%=================== ]

[===========================88.3%=================== ]

[===========================88.4%=================== ]

[===========================88.4%=================== ]

[===========================88.5%=================== ]

[===========================88.5%=================== ]

[===========================88.5%=================== ]

[===========================88.5%=================== ]

[===========================88.6%=================== ]

[===========================88.9%=================== ]

[===========================89.2%=================== ]

[===========================89.5%=================== ]

[===========================89.6%=================== ]

[===========================89.7%==================== ]

[===========================89.7%==================== ]

[===========================89.8%==================== ]

[===========================90.8%==================== ]

[===========================90.9%==================== ]

[===========================90.9%==================== ]

[===========================91.1%==================== ]

[===========================91.2%==================== ]

[===========================91.2%==================== ]

[===========================91.3%==================== ]

[===========================91.3%==================== ]

[===========================91.3%==================== ]

[===========================91.3%==================== ]

[===========================91.4%==================== ]

[===========================91.4%==================== ]

[===========================91.5%===================== ]

[===========================91.5%===================== ]

[===========================91.5%===================== ]

[===========================91.5%===================== ]

[===========================91.6%===================== ]

[===========================91.7%===================== ]

[===========================91.7%===================== ]

[===========================91.8%===================== ]

[===========================91.8%===================== ]

[===========================91.9%===================== ]

[===========================91.9%===================== ]

[===========================92.0%===================== ]

[===========================92.0%===================== ]

[===========================92.1%===================== ]

[===========================92.2%===================== ]

[===========================92.5%===================== ]

[===========================92.5%===================== ]

[===========================92.5%===================== ]

[===========================92.5%===================== ]

[===========================92.6%===================== ]

[===========================92.7%===================== ]

[===========================92.7%===================== ]

[===========================92.7%===================== ]

[===========================92.8%===================== ]

[===========================92.8%===================== ]

[===========================92.9%===================== ]

[===========================92.9%===================== ]

[===========================93.0%===================== ]

[===========================93.0%===================== ]

[===========================93.1%===================== ]

[===========================93.1%===================== ]

[===========================93.2%====================== ]

[===========================93.3%====================== ]

[===========================93.3%====================== ]

[===========================93.4%====================== ]

[===========================93.4%====================== ]

[===========================93.5%====================== ]

[===========================93.5%====================== ]

[===========================93.6%====================== ]

[===========================93.6%====================== ]

[===========================93.6%====================== ]

[===========================93.7%====================== ]

[===========================93.8%====================== ]

[===========================93.9%====================== ]

[===========================94.0%====================== ]

[===========================94.0%====================== ]

[===========================94.1%====================== ]

[===========================94.1%====================== ]

[===========================94.2%====================== ]

[===========================94.3%====================== ]

[===========================94.3%====================== ]

[===========================94.3%====================== ]

[===========================94.4%====================== ]

[===========================94.4%====================== ]

[===========================94.5%====================== ]

[===========================94.5%====================== ]

[===========================94.5%====================== ]

[===========================94.6%====================== ]

[===========================94.7%====================== ]

[===========================94.8%====================== ]

[===========================94.9%======================= ]

[===========================95.0%======================= ]

[===========================95.1%======================= ]

[===========================95.2%======================= ]

[===========================95.4%======================= ]

[===========================95.5%======================= ]

[===========================95.5%======================= ]

[===========================95.5%======================= ]

[===========================95.6%======================= ]

[===========================95.7%======================= ]

[===========================95.8%======================= ]

[===========================96.0%======================= ]

[===========================96.1%======================= ]

[===========================96.2%======================= ]

[===========================96.3%======================= ]

[===========================96.4%======================= ]

[===========================96.5%======================= ]

[===========================96.5%======================= ]

[===========================96.6%======================== ]

[===========================96.7%======================== ]

[===========================96.8%======================== ]

[===========================96.9%======================== ]

[===========================97.0%======================== ]

[===========================97.0%======================== ]

[===========================97.1%======================== ]

[===========================97.1%======================== ]

[===========================97.2%======================== ]

[===========================97.3%======================== ]

[===========================97.4%======================== ]

[===========================97.5%======================== ]

[===========================97.5%======================== ]

[===========================97.5%======================== ]

[===========================97.5%======================== ]

[===========================97.6%======================== ]

[===========================97.6%======================== ]

[===========================97.6%======================== ]

[===========================97.7%======================== ]

[===========================97.7%======================== ]

[===========================97.8%======================== ]

[===========================97.9%======================== ]

[===========================98.0%======================== ]

[===========================98.0%======================== ]

[===========================98.0%======================== ]

[===========================98.3%======================== ]

[===========================98.4%========================= ]

[===========================98.4%========================= ]

[===========================98.5%========================= ]

[===========================98.5%========================= ]

[===========================98.5%========================= ]

[===========================98.6%========================= ]

[===========================98.7%========================= ]

[===========================98.8%========================= ]

[===========================98.9%========================= ]

[===========================98.9%========================= ]

[===========================99.0%========================= ]

[===========================99.0%========================= ]

[===========================99.1%========================= ]

[===========================99.1%========================= ]

[===========================99.1%========================= ]

[===========================99.2%========================= ]

[===========================99.2%========================= ]

[===========================99.2%========================= ]

[===========================99.3%========================= ]

[===========================99.3%========================= ]

[===========================99.3%========================= ]

[===========================99.4%========================= ]

[===========================99.5%========================= ]

[===========================99.5%========================= ]

[===========================99.6%========================= ]

[===========================99.7%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[===========================99.9%========================= ]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]

[==========================100.0%==========================]
Operação de restauração concluída com êxito.
A operação foi concluída com êxito.



I n i c i a n d o v e r i f i c a þ Ò o d e a r q u i v o s . O p r o c e s s o l e v a r ß a l g u n s m i n u t o s p a r a s e r c o n c l u Ý d o .





I n i c i a n d o f a s e d e v e r i f i c a þ Ò o d e v e r i f i c a þ Ò o d o s i s t e m a .



V e r i f i c a þ Ò o 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 0 0 % c o n c l u Ý d a .




A P r o t e þ Ò o d e R e c u r s o s d o W i n d o w s n Ò o e n c o n t r o u n e n h u m a v i o l a þ Ò o d e i n t e g r i d a d e .




========= Fim de Powershell: =========

Ponto de Restauração criado com sucesso.
SystemRestore: On => completado
C:\Windows\System32\Drivers\etc\hosts => movido com sucesso
Hosts restaurado com sucesso.

=========== EmptyTemp: ==========

BITS transfer queue => 12869632 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 66738736 B
Java, Flash, Steam htmlcache => 1184 B
Windows/system/drivers => 110210 B
Edge => 10565 B
Chrome => 272632548 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 74588 B
NetworkService => 106384 B
Ramon.NOTEBOOK => 89817888 B

RecycleBin => 2380555729 B
EmptyTemp: => 2.6 GB de dados temporários Removidos.

================================


O sistema precisou ser reiniciado.

==== Fim de Fixlog 19:49:50 ====


PH disse:
Bom dia!

Eu lhe pergunto por causa disso.



Esse AutoKMS é usado para ativação ilegal do Windows e Office.

Dessa forma, pode usar todos os procedimentos para deixar o computador limpe e rápido, mas se continuar usando esses tipos de programas para burlar a ativação do sistema, os problemas sempre voltarão.


Entendi, PH. Bem, realmente o que ocorre é que a chave de ativação do Windows profissional venceu. Não usei nada para burlar. Como só faço uso domestico dele agora, não renovei. Será que tem como cancelar o uso profissional de forma legítima, ou teria que renovar a chave paga ou instalar outro windows sem ser o PRO?
R. Moran
"Podemos facilmente perdoar uma criança que tem medo do escuro; a real tragédia da vida é quando os homens têm medo da luz."
Platão
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas
#8 Por R. Moran
14/01/2021 - 21:09
Esse notebook fui eu que comprei. Porém o Windows Pro foi instalado pelo responsável pela TI de uma empresa que fazia parte. Foi comprado uma licença de uso comercial para seis usuários salvo engano, entre eles eu. Depois essa empresa passou por problemas durante a pandemia e veio a fechar. Sai e continuei com meu note. Depois de um tempo recebi uma notificação de chave vencida, e quando clico para ativar pede-se a renovação via pagamento. Não pretendo pagar, pois não faço parte da empresa e nem faço uso comercial do mesmo, correto?
R. Moran
"Podemos facilmente perdoar uma criança que tem medo do escuro; a real tragédia da vida é quando os homens têm medo da luz."
Platão
PH
PH Cyber Highlander Registrado
61.4K Mensagens 10.7K Curtidas
#10 Por PH
15/01/2021 - 09:10
R. Moran disse:
Esse notebook fui eu que comprei. Porém o Windows Pro foi instalado pelo responsável pela TI de uma empresa que fazia parte. Foi comprado uma licença de uso comercial para seis usuários salvo engano, entre eles eu. Depois essa empresa passou por problemas durante a pandemia e veio a fechar. Sai e continuei com meu note. Depois de um tempo recebi uma notificação de chave vencida, e quando clico para ativar pede-se a renovação via pagamento. Não pretendo pagar, pois não faço parte da empresa e nem faço uso comercial do mesmo, correto?


Bom dia!

Não conheço essas licenças do Windows provisórias, sei que para o Office 365 agora Microsoft 365 a licença são mensais ou anuais.
Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas
#11 Por R. Moran
15/01/2021 - 09:52
"ZHPDiag v2021.1.12.268 Por Nicolas Coolman (2021/01/12)"
~ ZHPDiag v2021.1.12.268 Por Nicolas Coolman (2021/01/12)
~ iniciado por Ramon (Administrator) (2021/01/15 09:30:30)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Status da versão:
~ Modo: Scanner
~ Relatório: C:\Users\Ramon.NOTEBOOK\Desktop\ZHPDiag.txt
~ Relatório: C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Inicialização do sistema: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 18362) =>.Microsoft Corporation

---\\ Navegadores Internet (3) - 1s
~ GCIE: Google Chrome v87.0.4280.141
~ MSIE: Internet Explorer v11.900.18362.0
~ OBIE: Microsoft Edge v87.0.664.57

---\\ Informações sobre os produtos Windows (3) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ (3) - 2s
Windows Defender W10 (Activate) (Protection)
Bitdefender Antivirus Free Edition v1.0.21.1109 (Protection)
Windows Defender W10 (Deactivate) (Protection)

---\\ Monitoramento dos softwares (1) - 2s
~ Adobe Acrobat Reader DC - Português (Surveillance)

---\\ Softwares d'optimização do sistema (1) - 2s
~ CCleaner v5.76 (Optimisation)

---\\ Softwares de partilha do PeerToPeer (P2P) (1) - 2s
~ qBittorrent 4.3.2 v4.3.2 (P2P)

---\\ Informações sobre o sistema (6) - 0s
~ Operating System: Intel64 Family 6 Model 61 Stepping 4, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4107.592 MB (51% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 64 GB (13%) free of 475 GB : OK =>.Disk Space

---\\ Modo de conexão ao sistema (3) - 0s
~ Computer Name: RAMON
~ User Name: Ramon
~ Logged in as Administrator

---\\ Enumeração das unidades dos discos (2) - 0s
~ Drive C: has 64 GB free of 475 GB (System)
~ Drive D: has GB free of 2 GB

---\\ Estado do Centro de Segurança do Windows (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Pesquisa particular de ficheiros genéricos (25) - 3s
[MD5.021A4A566AE86079929A482DCE9B76A7] - 01/07/2020 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [4624880] =>.Microsoft®
[MD5.F68AF942FD7CCC0E7BAB1A2335D2AD26] - 19/03/2019 - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [71168] [Unsigned] =>.Microsoft Corporation
[MD5.E83650F70459A027AA596E1A73C961A1] - 28/11/2019 - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) -- C:\WINDOWS\System32\Wininit.exe [398728] [Unsigned] =>.Microsoft Corporation
[MD5.5D2F4F7CCC70ADCFEE99C56CBF09F18E] - 08/05/2020 - (.Microsoft Corporation - Internet Extensions para Win32.) -- C:\WINDOWS\System32\wininet.dll [5040640] [Unsigned] =>.Microsoft Corporation
[MD5.F85DEFC2BE480CB713D2F179CB5782E0] - 08/05/2020 - (.Microsoft Corporation - Aplicativo de Logon do Windows.) -- C:\WINDOWS\System32\Winlogon.exe [845312] [Unsigned] =>.Microsoft Corporation
[MD5.8BA955BD719207F590EC8C5F2B46AE59] - 08/05/2020 - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) -- C:\WINDOWS\System32\sppcomapi.dll [307712] [Unsigned] =>.Microsoft Corporation
[MD5.B0F1AF6795A83628F7D785FC4621507E] - 01/07/2020 - (.Microsoft Corporation - DLL da API de cliente DNS.) -- C:\WINDOWS\System32\dnsapi.dll [822272] =>.Microsoft®
[MD5.23F45825244CFCB11CC6355690F3FFAB] - 01/07/2020 - (.Microsoft Corporation - DLL da API de cliente DNS.) -- C:\WINDOWS\Syswow64\dnsapi.dll [592944] =>.Microsoft®
[MD5.95336878FE34E39BC21F8BF5C60448C0] - 01/07/2020 - (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\System32\wuaueng.dll [3109376] [Unsigned] =>.Microsoft Corporation
[MD5.67FA68C9522EACE1A2BD44486FFC8771] - 01/07/2020 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [661816] [Unsigned] =>.Microsoft Corporation
[MD5.30D7EEDAB3671A5DF808D1836CCACF56] - 08/05/2020 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [30008] [Unsigned] =>.Microsoft Corporation
[MD5.3E9C20ED02FAA6D194C060BC6E7D587E] - 12/12/2019 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [100352] [Unsigned] =>.Microsoft Corporation
[MD5.81E3779064C04790E30F25770F0AEADD] - 19/03/2019 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [173056] [Unsigned] =>.Microsoft Corporation
[MD5.D974C10E19DDC10622E30904AEE16FA3] - 19/03/2019 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [151040] [Unsigned] =>.Microsoft Corporation
[MD5.1D742547071FC1436ED72A3F9DB6E1F0] - 08/05/2020 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [114688] [Unsigned] =>.Microsoft Corporation
[MD5.B475892255B02D33CF29B24FBD4AFDC9] - 19/03/2019 - (.Microsoft Corporation - Driver de porta i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [119296] [Unsigned] =>.Microsoft Corporation
[MD5.5E05C0FEA671B910FEBC634E796C38B5] - 19/03/2019 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [224768] [Unsigned] =>.Microsoft Corporation
[MD5.90D2833915ACAF0F11F99B330CF2250A] - 01/07/2020 - (.Microsoft Corporation - Minirdr SMB do Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [561464] [Unsigned] =>.Microsoft Corporation
[MD5.729ED379D3A960CFBE02C7634651AC63] - 28/11/2019 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [337408] [Unsigned] =>.Microsoft Corporation
[MD5.CA25673ED59E3B133B6EC7C043296FEB] - 08/05/2020 - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2698040] [Unsigned] =>.Microsoft Corporation
[MD5.AC682BC99BECA3A6C8C71234A9BC4225] - 19/03/2019 - (.Microsoft Corporation - Driver de porta paralela.) -- C:\WINDOWS\System32\drivers\Parport.sys [108032] [Unsigned] =>.Microsoft Corporation
[MD5.555E33527CC3C34620E49F5F86C8F7B0] - 19/03/2019 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [112128] [Unsigned] =>.Microsoft Corporation
[MD5.51D49770FD9D2E1956833C1F4D992893] - 28/11/2019 - (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Micros.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [167936] [Unsigned] =>.Microsoft Corporation
[MD5.9AF99FB2DA176C88C68D886046C56B01] - 19/03/2019 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [132616] [Unsigned] =>.Microsoft Corporation
[MD5.7764E62EF94DDA90E87309E739F6970E] - 08/05/2020 - (.Microsoft Corporation - Driver de Cópia de Sombra de Volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [429880] [Unsigned] =>.Microsoft Corporation

---\\ Serviços NT não desativados (59) - 4s
O23 - Service: C:\WINDOWS\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Construtor de Pontos de Extremidade de Áudi.) - C:\WINDOWS\System32\AudioEndpointBuilder.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Serviço de Áudio do Windows.) - C:\WINDOWS\System32\Audiosrv.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\bfe.dll (BFE) . (.Microsoft Corporation - Mecanismo de Filtragem Básica.) - C:\WINDOWS\System32\bfe.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\qmgr.dll (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) - C:\WINDOWS\System32\qmgr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Process State Manager (PSM) Service.) - C:\WINDOWS\System32\psmsrv.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\cdpusersvc.dll (CDPUserSvc) . (.Microsoft Corporation - Componentes de Usuário CDP da Microsoft (R).) - C:\WINDOWS\System32\CDPUserSvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Serviço de Usuário da Plataforma de Dispositivos Conectados (CDPUserSvc_3cbfd) . (.Microsoft Corporation - Processo de Host para Serviços do Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\Windows\System32\coremessaging.dll (CoreMessagingRegistrar) . (.Microsoft Corporation - Microsoft CoreMessaging Dll.) - C:\Windows\System32\coremessaging.dll =>.Microsoft®
O23 - Service: C:\WINDOWS\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Serviços de criptografia.) - C:\WINDOWS\System32\cryptsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\das.dll (DeviceAssociationService) . (.Microsoft Corporation - Serviço de Associação de Dispositivo.) - C:\WINDOWS\System32\das.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - Serviço do Cliente DHCP.) - C:\Windows\System32\dhcpcore.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\diagtrack.dll (DiagTrack) . (.Microsoft Corporation - Rastreamento de Diagnóstico do Microsoft Wi.) - C:\WINDOWS\System32\diagtrack.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\dispbroker.desktop.dll (DispBrokerDesktopSvc) . (.Microsoft Corporation - Agente de Exibição da Área de Trabalho.) - C:\WINDOWS\System32\DispBroker.Desktop.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - Serviço de resolução de cache do DNS.) - C:\WINDOWS\System32\dnsrslvr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\dosvc.dll (DoSvc) . (.Microsoft Corporation - Processo de Host para Serviços do Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\WINDOWS\System32\dusmsvc.dll (DusmSvc) . (.Microsoft Corporation - Serviço de Uso de Dados.) - C:\WINDOWS\System32\dusmsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Serviço Microsoft Edge Update (edgeupdate) (edgeupdate) . (.Microsoft Corporation - Microsoft Edge Update.) - C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe =>.Microsoft®
O23 - Service: C:\WINDOWS\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Serviço de log de eventos.) - C:\WINDOWS\System32\wevtsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Serviço de Cache de Fontes do Windows.) - C:\WINDOWS\System32\FntCache.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) - C:\WINDOWS\System32\gpsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Bitdefender Antivirus Free Edition (gzserv) . (.Bitdefender - Bitdefender Antivirus Free Edition.) - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe =>.Bitdefender SRL®
O23 - Service: C:\WINDOWS\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) - C:\WINDOWS\System32\iphlpsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - DLL de Serviço do Servidor.) - C:\WINDOWS\System32\srvsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - DLL do Serviço de Estação de Trabalho.) - C:\WINDOWS\System32\wkssvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\lsm.dll (LSM) . (.Microsoft Corporation - Serviço do Gerenciador de Sessão Local.) - C:\WINDOWS\System32\lsm.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\moshost.dll (MapsBroker) . (.Microsoft Corporation - Gerenciador de Mapas Baixados.) - C:\WINDOWS\System32\moshost.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (mpssvc) . (.Microsoft Corporation - Serviço de Proteção Microsoft.) - C:\WINDOWS\System32\mpssvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Net Driver HPZ12 (Net Driver HPZ12) . (.Hewlett-Packard - Dot4Net Module.) - C:\Windows\System32\HPZinw12.dll [Unsigned] =>.Hewlett-Packard
O23 - Service: C:\WINDOWS\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Reconhecimento de Locais de Rede 2.) - C:\WINDOWS\System32\nlasvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Servidor RPC de Interface de Repositório de.) - C:\WINDOWS\System32\nsisvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\APHostRes.dll (OneSyncSvc) . (.Microsoft Corporation - Accounts Host Service.) - C:\WINDOWS\System32\APHostService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Host de Sincronização_3cbfd (OneSyncSvc_3cbfd) . (.Microsoft Corporation - Processo de Host para Serviços do Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: Pml Driver HPZ12 (Pml Driver HPZ12) . (.Hewlett-Packard - PmlDrv Module.) - C:\WINDOWS\system32\HPZipm12.dll [Unsigned] =>.Hewlett-Packard
O23 - Service: C:\WINDOWS\System32\umpo.dll (Power) . (.Microsoft Corporation - Serviço de Energia no Modo de Usuário.) - C:\WINDOWS\System32\umpo.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\WINDOWS\System32\profsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\rasmans.dll (RasMan) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) - C:\WINDOWS\System32\rasmans.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - Mapeador de Ponto de Extremidade RPC.) - C:\WINDOWS\System32\RpcEpMap.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\WINDOWS\System32\rpcss.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) - C:\WINDOWS\System32\schedsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\Sens.dll (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) - C:\WINDOWS\System32\sens.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\SgrmBroker.exe,-100 (SgrmBroker) . (.Microsoft Corporation - Serviço System Guard Runtime Monitor Broker.) - C:\WINDOWS\System32\SgrmBroker.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) - C:\Windows\System32\shsvcs.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Aplicativo de subsistema de spooler.) - C:\WINDOWS\System32\spoolsv.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Serviço da Plataforma de Proteção de Softwa.) - C:\WINDOWS\System32\sppsvc.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wiaservc.dll (stisvc) . (.Microsoft Corporation - Serviço dos dispositivos de imagem fixa.) - C:\WINDOWS\System32\wiaservc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Host do Serviço SysMain.) - C:\WINDOWS\System32\sysmain.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - Agente de Eventos do Sistema.) - C:\WINDOWS\System32\SystemEventsBrokerServer.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\themeservice.dll (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) - C:\WINDOWS\System32\themeservice.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\usermgr.dll (UserManager) . (.Microsoft Corporation - UserMgr.) - C:\WINDOWS\System32\usermgr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\usosvc.dll (UsoSvc) . (.Microsoft Corporation - Atualizar Session Orchestrator Service.) - C:\WINDOWS\System32\usosvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - DLL do Serviço do Gerenciador de Conexões d.) - C:\WINDOWS\System32\wcmsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\WINDOWS\System32\wbem\WMIsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wlansvc.dll (WlanSvc) . (.Microsoft Corporation - DLL do Serviço de Configuração Automática d.) - C:\WINDOWS\System32\wlansvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wpnservice.dll (WpnService) . (.Microsoft Corporation - Serviço do Sistema de Notificação por Push.) - C:\WINDOWS\System32\WpnService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\WpnUserService.dll (WpnUserService) . (.Microsoft Corporation - Serviço de Usuário de Notificação por Push.) - C:\WINDOWS\System32\WpnUserService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Serviço de Usuário de Notificações por Push do Windows_3cbfd (WpnUserService_3cbfd) . (.Microsoft Corporation - Processo de Host para Serviços do Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\WINDOWS\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Serviço Central de Segurança do Windows.) - C:\WINDOWS\System32\wscsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Indexador do Microsoft Windows Search.) - C:\Windows\System32\SearchIndexer.exe [Unsigned] =>.Microsoft Corporation

---\\ Serviços não Microsoft (SR=Executados, SS=Parados) (91) - 22s
SR - Boot [19/03/2019] [ 107528] (3ware) . (.LSI.) - C:\WINDOWS\System32\drivers\3ware.sys =>.Microsoft Windows®
SR - Disabl [03/11/2020] [ 170056] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Inc..) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Inc.®
SR - Disabl [04/09/2018] [ 335872] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Boot [19/03/2019] [ 1135632] (ADP80XX) . (.PMC-Sierra.) - C:\WINDOWS\System32\drivers\ADP80XX.SYS =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 18432] AMD GPIO Client Driver (amdgpio2) . (.Advanced Micro Devices, Inc.) - C:\WINDOWS\System32\drivers\amdgpio2.sys [Unsigned] =>.Advanced Micro Devices, Inc
SR - Demand [19/03/2019] [ 37888] AMD I2C Controller Service (amdi2c) . (.Advanced Micro Devices, Inc.) - C:\WINDOWS\System32\drivers\amdi2c.sys [Unsigned] =>.Advanced Micro Devices, Inc
SR - Boot [19/03/2019] [ 83464] (amdsata) . (.Advanced Micro Devices.) - C:\WINDOWS\System32\drivers\amdsata.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 259600] (amdsbs) . (.AMD Technologies Inc..) - C:\WINDOWS\System32\drivers\amdsbs.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 27176] (amdxata) . (.Advanced Micro Devices.) - C:\WINDOWS\System32\drivers\amdxata.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 132112] Adaptec SAS/SATA-II RAID S (arcsas) . (.PMC-Sierra, Inc..) - C:\WINDOWS\System32\drivers\arcsas.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 4233728] Qualcomm Atheros Extens (athr) . (.Qualcomm Atheros Communications, Inc..) - C:\WINDOWS\System32\drivers\athw8x.sys [Unsigned] =>.Qualcomm Atheros Communications, Inc.
SR - Demand [17/04/2013] [ 593144] avckf (avckf) . (.BitDefender.) - C:\WINDOWS\System32\DRIVERS\avckf.sys =>.Bitdefender SRL®
SR - Boot [19/03/2019] [ 534032] QLogic Network Adapter VBD (b06bdrv) . (.QLogic Corporation.) - C:\WINDOWS\System32\drivers\bxvbda.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 9728] bcmfn2 Service (bcmfn2) . (...) - C:\WINDOWS\System32\drivers\bcmfn2.sys [Unsigned] =>.Broadcom Corporation
SR - System [02/07/2013] [ 121928] bdfwfpf (bdfwfpf) . (.Bitdefender SRL.) - C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys =>.Bitdefender SRL®
SR - Demand [13/07/2016] [ 610336] BtFilter (BtFilter) . (.Qualcomm Atheros.) - C:\WINDOWS\System32\DRIVERS\btfilter.sys =>.Microsoft Windows Hardware Compatibility Publisher®
SR - Boot [19/03/2019] [ 319528] (cht4iscsi) . (.Chelsio Communications.) - C:\WINDOWS\System32\drivers\cht4sx64.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 1866768] Chelsio Virtual Bus Driver (cht4vbd) . (.Chelsio Communications.) - C:\WINDOWS\System32\drivers\cht4vx64.sys =>.Microsoft Windows®
SR - Disabl [25/09/2017] [ 300624] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel(R) pGFX®
SR - Disabl [27/09/2016] [ 143144] Serviço Atualização do Dropbox (dbupdate) (dbupdate) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
SR - Disabl [27/09/2016] [ 143144] Serviço Atualização do Dropbox (dbupdatem) (dbupdatem) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
SR - Disabl [04/12/2019] [ 51024] DbxSvc (DbxSvc) . (.Dropbox, Inc..) - C:\WINDOWS\System32\DbxSvc.exe =>.Dropbox, Inc®
SR - Demand [05/09/2016] [ 131712] SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) (dg_ssudbus) . (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\DRIVERS\ssudbus.sys =>.Samsung Electronics CO., LTD.®
SS - Demand [19/10/2018] [ 3729512] Disc Soft Lite Bus Service (Disc Soft Lite Bus Service) . (.Disc Soft Ltd.) - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe =>.AVB Disc Soft, SIA®
SR - Demand [17/10/2016] [ 30264] DAEMON Tools Lite Virt (dtlitescsibus) . (.Disc Soft Ltd.) - C:\WINDOWS\System32\drivers\dtlitescsibus.sys =>.Disc Soft Ltd®
SR - Demand [17/10/2016] [ 47672] DAEMON Tools Lite Virt (dtliteusbbus) . (.Disc Soft Ltd.) - C:\WINDOWS\System32\drivers\dtliteusbbus.sys =>.Disc Soft Ltd®
SR - Boot [19/03/2019] [ 3419176] QLogic 10 Gigabit Ethernet Ada (ebdrv) . (.QLogic Corporation.) - C:\WINDOWS\System32\drivers\evbda.sys =>.Microsoft Windows®
SR - Disabl [05/01/2021] [ 1431656] Google Chrome Elevation Service (GoogleChromeElevationService) . (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\elevation_service.exe =>.Google LLC®
SR - Disabl [12/08/2016] [ 154440] Serviço do Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Disabl [12/08/2016] [ 154440] Serviço do Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Disabl [31/07/2014] [ 136120] Google Updater Service (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe =>.Google Inc®
SR - System [22/04/2013] [ 148696] gzflt (gzflt) . (.BitDefender LLC.) - C:\WINDOWS\System32\DRIVERS\gzflt.sys =>.Bitdefender SRL®
SR - Auto [02/03/2016] [ 79552] Bitdefender Antivirus Free Edition (gzserv) . (.Bitdefender.) - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe =>.Bitdefender SRL®
SR - Disabl [17/10/2011] [ 13824] HP DS Service (HP DS Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [Unsigned] =>.Hewlett-Packard Company
SR - Disabl [18/11/2012] [ 174592] HP LaserJet Service (HP LaserJet Service) . (.HP.) - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [Unsigned] =>.HP
SR - Boot [19/03/2019] [ 64528] (HpSAMD) . (.Hewlett-Packard Company.) - C:\WINDOWS\System32\drivers\HpSAMD.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 36352] Intel Serial IO GPIO Controlle (iagpio) . (.Intel(R) Corporation.) - C:\WINDOWS\System32\drivers\iagpio.sys [Unsigned] =>.Intel(R) Corporation
SR - Demand [19/03/2019] [ 91136] Intel(R) Serial IO I2C Host Cont (iai2c) . (.Intel(R) Corporation.) - C:\WINDOWS\System32\drivers\iai2c.sys [Unsigned] =>.Intel(R) Corporation
SR - Demand [19/03/2019] [ 79360] Intel(R) S (iaLPSS2i_GPIO2) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 93184] In (iaLPSS2i_GPIO2_BXT_P) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 112128] Intel( (iaLPSS2i_GPIO2_CNL) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 96256] Intel( (iaLPSS2i_GPIO2_GLK) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 171520] Intel(R) Seria (iaLPSS2i_I2C) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 175104] Intel( (iaLPSS2i_I2C_BXT_P) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 180736] Intel(R) S (iaLPSS2i_I2C_CNL) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 177664] Intel(R) S (iaLPSS2i_I2C_GLK) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 38128] Intel(R) Serial IO (iaLPSSi_GPIO) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys =>.Intel Corporation - Client Components Group®
SR - Demand [19/03/2019] [ 113152] Intel(R) Serial IO I (iaLPSSi_I2C) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [Unsigned] =>.Intel Corporation
SR - Boot [19/03/2019] [ 885048] Intel Chipset SATA RAI (iaStorAVC) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaStorAVC.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 411960] Intel RAID Controller Wi (iaStorV) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaStorV.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 566800] Mellanox InfiniBand Bus/A (ibbus) . (.Mellanox.) - C:\WINDOWS\System32\drivers\ibbus.sys =>.Microsoft Windows®
SR - Disabl [22/10/2004] [ 73728] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [Unsigned] =>.Macrovision Corporation
SR - Demand [25/09/2017] [ 7971792] (igfx) . (.Intel Corporation.) - C:\WINDOWS\System32\DRIVERS\igdkmd64.sys =>.Intel(R) pGFX®
SR - Disabl [25/09/2017] [ 373712] Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation.) - C:\WINDOWS\System32\igfxCUIService.exe =>.Intel(R) pGFX®
SR - Demand [09/07/2015] [ 4522752] Service for Realtek HD Audio (WDM) (IntcAzAudAddService) . (.Realtek Semiconductor Corp..) - C:\WINDOWS\System32\drivers\RTKVHD64.sys =>.Realtek Semiconductor Corp®
SR - Demand [12/05/2016] [ 481768] Áudio Intel(R) para telas (IntcDAud) . (.Intel(R) Corporation.) - C:\WINDOWS\System32\drivers\IntcDAud.sys =>.Intel(R) OWR®
SR - Boot [19/03/2019] [ 148520] (ItSas35i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\ItSas35i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 109064] (LSI_SAS) . (.LSI Corporation.) - C:\WINDOWS\System32\drivers\lsi_sas.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 124448] (LSI_SAS2i) . (.LSI Corporation.) - C:\WINDOWS\System32\drivers\lsi_sas2i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 128528] (LSI_SAS3i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\lsi_sas3i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 82960] (LSI_SSS) . (.LSI Corporation.) - C:\WINDOWS\System32\drivers\lsi_sss.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 59920] (megasas) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\megasas.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 75280] (megasas2i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\MegaSas2i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 94736] (megasas35i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\megasas35i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 576016] (megasr) . (.LSI Corporation, Inc..) - C:\WINDOWS\System32\drivers\megasr.sys =>.Microsoft Windows®
SR - Demand [23/06/2015] [ 192312] Intel(R) Management Engine Interfa (MEIx64) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
SR - Demand [19/03/2019] [ 1150480] Mellanox ConnectX Bus E (mlx4_bus) . (.Mellanox.) - C:\WINDOWS\System32\drivers\mlx4_bus.sys =>.Microsoft Windows®
SR - Disabl [03/05/2016] [ 146888] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SR - Boot [19/03/2019] [ 64016] (mvumis) . (.Marvell Semiconductor, Inc..) - C:\WINDOWS\System32\drivers\mvumis.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 153616] NetworkDirect Service (ndfltr) . (.Mellanox.) - C:\WINDOWS\System32\drivers\ndfltr.sys =>.Microsoft Windows®
SR - Auto [31/07/2012] [ 50688] Net Driver HPZ12 (Net Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\HPZinw12.dll [Unsigned] =>.Hewlett-Packard
SR - Boot [19/03/2019] [ 150544] (nvraid) . (.NVIDIA Corporation.) - C:\WINDOWS\System32\drivers\nvraid.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 166408] (nvstor) . (.NVIDIA Corporation.) - C:\WINDOWS\System32\drivers\nvstor.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 58896] (percsas2i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\percsas2i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 68624] (percsas3i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\percsas3i.sys =>.Microsoft Windows®
SR - Auto [31/07/2012] [ 66048] Pml Driver HPZ12 (Pml Driver HPZ12) . (.Hewlett-Packard.) - C:\WINDOWS\system32\HPZipm12.dll [Unsigned] =>.Hewlett-Packard
SR - Demand [19/03/2019] [ 662528] Realtek RT640 NT Dri (rt640x64) . (.Realtek.) - C:\WINDOWS\System32\drivers\rt640x64.sys [Unsigned] =>.Realtek
SR - Demand [03/07/2015] [ 410880] Realtek USB Card Reader - UER (RTSUER) . (.Realsil Semiconductor Corporation.) - C:\WINDOWS\System32\Drivers\RtsUer.sys =>.Realtek Semiconductor Corp®
SR - Demand [04/06/2015] [ 21984] semav6msr64 (semav6msr64) . (.Intel(R) Code Signing External.) - C:\Windows\system32\drivers\semav6msr64.sys =>.Intel(R) Code Signing External®
SR - Boot [19/03/2019] [ 45072] (SiSRaid2) . (.Silicon Integrated Systems Corp..) - C:\WINDOWS\System32\drivers\SiSRaid2.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 81936] (SiSRaid4) . (.Silicon Integrated Systems.) - C:\WINDOWS\System32\drivers\sisraid4.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 220176] (SmartSAMD) . (.Microsemi Corportation.) - C:\WINDOWS\System32\drivers\SmartSAMD.sys =>.Microsoft Windows®
SR - Demand [05/09/2016] [ 165504] SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) (ssudmdm) . (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\DRIVERS\ssudmdm.sys =>.Samsung Electronics CO., LTD.®
SR - Boot [19/03/2019] [ 31240] (stexstor) . (.Promise Technology, Inc..) - C:\WINDOWS\System32\drivers\stexstor.sys =>.Microsoft Windows®
SR - Demand [05/08/2015] [ 56520] Synaptics HID Service (SynRMIHID) . (.Synaptics Incorporated.) - C:\WINDOWS\System32\DRIVERS\SynRMIHID.sys =>.Synaptics Incorporated®
SR - Boot [28/05/2013] [ 382536] trufos (trufos) . (.BitDefender S.R.L..) - C:\WINDOWS\System32\DRIVERS\trufos.sys =>.Bitdefender SRL®
SR - Boot [19/03/2019] [ 166928] (vsmraid) . (.VIA Technologies Inc.,Ltd.) - C:\WINDOWS\System32\drivers\vsmraid.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 305672] VIA StorX Storage RAID Co (VSTXRAID) . (.VIA Corporation.) - C:\WINDOWS\System32\drivers\vstxraid.sys =>.Microsoft Windows®
SR - Demand [16/08/2016] [ 159936] wdm_usb (wdm_usb) . (.MBB.) - C:\WINDOWS\System32\DRIVERS\usb2ser.sys =>.NGO®
SR - Demand [19/03/2019] [ 37928] WinMad Service (WinMad) . (.Mellanox.) - C:\WINDOWS\System32\drivers\winmad.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 77832] WinVerbs Service (WinVerbs) . (.Mellanox.) - C:\WINDOWS\System32\drivers\winverbs.sys =>.Microsoft Windows®

---\\ Aplicações iniciadas por registo & pastas (11) - 3s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Security notification icon.) -- C:\WINDOWS\system32\SecurityHealthSystray.exe [Unsigned] =>.Microsoft Corporation
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] . (.Disc Soft Ltd - DAEMON Tools Lite Agent.) -- C:\Program Files\DAEMON Tools Lite\DTAgent.exe =>.AVB Disc Soft, SIA®
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKLM\..\Wow6432Node\Run: [StatusAlerts] . (.Hewlett-Packard Company - HPStatusAlerts.) -- C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe =>.Hewlett-Packard Company®
O4 - HKLM\..\Wow6432Node\Run: [Dropbox] . (.Dropbox, Inc. - Dropbox.) -- C:\Program Files (x86)\Dropbox\Client\Dropbox.exe =>.Dropbox, Inc®
O4 - HKUS\S-1-5-21-2109982156-1193874355-445741488-1002\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - HKUS\S-1-5-21-2109982156-1193874355-445741488-1002\..\Run: [DAEMON Tools Lite Automount] . (.Disc Soft Ltd - DAEMON Tools Lite Agent.) -- C:\Program Files\DAEMON Tools Lite\DTAgent.exe =>.AVB Disc Soft, SIA®
O4 - HKUS\S-1-5-21-2109982156-1193874355-445741488-1002\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd®

---\\ Processos lançados (6) - 3s
[MD5.995688E8FE683E2DA66D7C83A67C1E5C] - (.Bitdefender - Bitdefender Antivirus Free Edition.) -- C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [79552] [PID.1520] =>.Bitdefender SRL®
[MD5.563DD007EF7FCFD1E3B838FF280AA69C] - (.Bitdefender - Bitdefender Antivirus Free Edition.) -- C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe [266120] [PID.4380] =>.Bitdefender SRL®
[MD5.7D245F2BE526C4152A73C6FBDD9B5EC2] - (...) -- C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe [943928] [PID.3424] =>.Microsoft®
[MD5.B3E3C199E4F88A1BC5889A2BAD21D656] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.54.91.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe [182272] [PID.5636] [Unsigned] =>.Microsoft Corporation
[MD5.398A594D93A0C4FCF26DE674407CA57A] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [32440376] [PID.7084] =>.Piriform Software Ltd®
[MD5.82C1F194685DD2E5EAA5F534FB892CD9] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPDiag3.exe [3284104] [PID.7364] [Unsigned] =>.Nicolas Coolman

---\\ Google Chrome, Arranque,Pesquisa,Extensões (11) - 1s
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [Temp]
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [aomjekmpappghadlogpigifkghlmebjk] http://dictanote.co/accounts/signup
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [cfhdojbkjhnklbpkdaibdccddilifddb] eyeo GmbH =>.Eyeo GmbH
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [cppjkneekbjaeellbfkmgnhonkkjfpdn] Clear Cache =>.Benjamin Bojko
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [hfknjgplnkgjihghcidajejfmldhibfm] http://voicenote.in/live/app.html
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [Ramon][User Data\Default\Extensions] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
G2 - GCE: Preference [Ramon][User Data\Default\Local Extension Settings] [cfhdojbkjhnklbpkdaibdccddilifddb] =>.eyeo GmbH {AdBlock Plus}
G2 - GCE: Preference [Ramon][User Data\Default\Local Extension Settings] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [Ramon][User Data\Default\Managed Extension Settings] [cfhdojbkjhnklbpkdaibdccddilifddb] =>.eyeo GmbH {AdBlock Plus}
G2 - GCE: Preference [Ramon][User Data\Default\Sync Extension Settings] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] =>.Google Inc. {Chrome Media Router}

---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (4) - 1s
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[EMAIL]e10srollout@mozilla.org.xpi[/EMAIL] [Unsigned] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[EMAIL]firefox@getpocket.com.xpi[/EMAIL] [Unsigned] =>.Mozilla Corporation
P2 - EXT FILE: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[EMAIL]loop@mozilla.org.xpi[/EMAIL] [Unsigned]
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_154.dll =>.Adobe Systems Incorporated

---\\ Internet Explorer, Arranque, Pesquisa, Phishing (15) - 2s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ =>.Google Inc.
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navegador da Internet.) (11.00.18362.628 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\\ INTERNET EXPLORER, site confiável e site sensível (94) - 2s
~ IE Restricted Site Potentially Unwanted: 007guard.com
~ IE Restricted Site Potentially Unwanted: 008i.com
~ IE Restricted Site Potentially Unwanted: 008k.com
~ IE Restricted Site Potentially Unwanted: 00hq.com
~ IE Restricted Site Potentially Unwanted: 010402.com
~ IE Restricted Site Potentially Unwanted: 032439.com
~ IE Restricted Site Potentially Unwanted: 0scan.com
~ IE Restricted Site Potentially Unwanted: 1-2005-search.com
~ IE Restricted Site Potentially Unwanted: 1-domains-registrations.com
~ IE Restricted Site Potentially Unwanted: 1000gratisproben.com
~ IE Restricted Site Potentially Unwanted: 1001namen.com
~ IE Restricted Site Potentially Unwanted: 100888290cs.com
~ IE Restricted Site Potentially Unwanted: 100sexlinks.com
~ IE Restricted Site Potentially Unwanted: 10sek.com
~ IE Restricted Site Potentially Unwanted: 123fporn.info
~ IE Restricted Site Potentially Unwanted: 123haustiereundmehr.com
~ IE Restricted Site Potentially Unwanted: 123moviedownload.com
~ IE Restricted Site Potentially Unwanted: 123simsen.com
~ IE Restricted Site Potentially Unwanted: 123topsearch.com
~ IE Restricted Site Potentially Unwanted: 125sms.co.uk
~ IE Restricted Site Potentially Unwanted: 125sms.com
~ IE Restricted Site Potentially Unwanted: 132.com
~ IE Restricted Site Potentially Unwanted: 1337-crew.to
~ IE Restricted Site Potentially Unwanted: 1337crew.info
~ IE Restricted Site Potentially Unwanted: 136136.net
~ IE Restricted Site Potentially Unwanted: 150freesms.de
~ IE Restricted Site Potentially Unwanted: 163ns.com
~ IE Restricted Site Potentially Unwanted: 17-plus.com
~ IE Restricted Site Potentially Unwanted: 171203.com
~ IE Restricted Site Potentially Unwanted: 17concepts.info
~ IE Restricted Site Potentially Unwanted: 1800searchonline.com
~ IE Restricted Site Potentially Unwanted: 180searchassistant.com
~ IE Restricted Site Potentially Unwanted: 180solutions.com
~ IE Restricted Site Potentially Unwanted: 1987324.com
~ IE Restricted Site Potentially Unwanted: 1ghporn.info
~ IE Restricted Site Potentially Unwanted: 1importantiamreal.com
~ IE Restricted Site Potentially Unwanted: 1mybigdreamnowreal.com
~ IE Restricted Site Potentially Unwanted: 1sexparty.com
~ IE Restricted Site Potentially Unwanted: 1sms.de
~ IE Restricted Site Potentially Unwanted: 1spybot.com
~ IE Restricted Site Potentially Unwanted: 1stantivirus.com
~ IE Restricted Site Potentially Unwanted: 1stpagehere.com
~ IE Restricted Site Potentially Unwanted: 1stsearchportal.com
~ IE Restricted Site Potentially Unwanted: 2-2005-search.com
~ IE Restricted Site Potentially Unwanted: 2006ooo.com
~ IE Restricted Site Potentially Unwanted: 2007-download.com
~ IE Restricted Site Potentially Unwanted: 2008-search-destroy.com
~ IE Restricted Site Potentially Unwanted: 2008-viewer.com
~ IE Restricted Site Potentially Unwanted: 2008firefox.com
~ IE Restricted Site Potentially Unwanted: 2008search-destroy.com
~ IE Restricted Site Potentially Unwanted: 2009--access.com
~ IE Restricted Site Potentially Unwanted: 2009-edition.com
~ IE Restricted Site Potentially Unwanted: 2009-phone.com
~ IE Restricted Site Potentially Unwanted: 2009-version.info
~ IE Restricted Site Potentially Unwanted: 2009antivirpro.com
~ IE Restricted Site Potentially Unwanted: 2009search-destroy.com
~ IE Restricted Site Potentially Unwanted: 2011-kilos-verlieren.eu
~ IE Restricted Site Potentially Unwanted: 2020search.com
~ IE Restricted Site Potentially Unwanted: 20x2p.com
~ IE Restricted Site Potentially Unwanted: 21dice.net
~ IE Restricted Site Potentially Unwanted: 24-7pharmacy.info
~ IE Restricted Site Potentially Unwanted: 24-7searching-and-more.com
~ IE Restricted Site Potentially Unwanted: 247fxxx.info
~ IE Restricted Site Potentially Unwanted: 24teen.com
~ IE Restricted Site Potentially Unwanted: 2ndpower.com
~ IE Restricted Site Potentially Unwanted: 2rfsex.info
~ IE Restricted Site Potentially Unwanted: 2search.com
~ IE Restricted Site Potentially Unwanted: 2search.org
~ IE Restricted Site Potentially Unwanted: 2squared.com
~ IE Restricted Site Potentially Unwanted: 2vgporn.info
~ IE Restricted Site Potentially Unwanted: 3-2005-search.com
~ IE Restricted Site Potentially Unwanted: 30horasdesexoonline.com
~ IE Restricted Site Potentially Unwanted: 31columns.com
~ IE Restricted Site Potentially Unwanted: 321-gratis-sms.com
~ IE Restricted Site Potentially Unwanted: 3322.org
~ IE Restricted Site Potentially Unwanted: 365fporn.info
~ IE Restricted Site Potentially Unwanted: 365sites.info
~ IE Restricted Site Potentially Unwanted: 365soft.info
~ IE Restricted Site Potentially Unwanted: 36site.com
~ IE Restricted Site Potentially Unwanted: 3721.com
~ IE Restricted Site Potentially Unwanted: 39-93.com
~ IE Restricted Site Potentially Unwanted: 3bay.it
~ IE Restricted Site Potentially Unwanted: 3dgsex.info
~ IE Restricted Site Potentially Unwanted: 3mates.com
~ IE Restricted Site Potentially Unwanted: 3wgporn.info
~ IE Restricted Site Potentially Unwanted: 3x-festival.com
~ IE Restricted Site Potentially Unwanted: 3x-galls.com
~ IE Restricted Site Potentially Unwanted: 3xclipsonline.com
~ IE Restricted Site Potentially Unwanted: 3xcurves.com
~ IE Restricted Site Potentially Unwanted: 3xfestival.com
~ IE Restricted Site Potentially Unwanted: 3xmiracle.com
~ IE Restricted Site Potentially Unwanted: 3xmoviesblog.com
~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 7882(Bad)
~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 7882(Bad)

---\\ Microsoft Edge, Plugins,Arranque,Pesquisa,Extensões (1) - 0s
E2 - GCE: Preference [Ramon][User Data\Default\Local Extension Settings] [jdiccldimpdaibmpdkjnbmckianbfold] =>.Microsoft Corporation

---\\ Internet Explorer, Gestão do Proxy (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Análise das linhas, Carregamento Automático de programas (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Redireção do ficheiro Hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (0)

---\\ Browser Helper Objects do navegador (2) - 0s
O2 - BHO: IEToEdge BHO [64Bits] - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} . (.Microsoft Corporation - IEToEdge BHO.) -- C:\Program Files (x86)\Microsoft\Edge\Application\87.0.664.57\BHO\ie_to_edge_bho_64.dll =>.Microsoft®
O2 - BHO: Microsoft OneDrive for Business Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®

---\\ Atalhos globais Startup (142) - 19s
O4 - GS\Desktop [Administrador]: Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe - Atalho.lnk . (.3DMGAME - Age of Empires II Definitive Edition v1.0-B.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Administrador]: Age of Empires II Definitive Edition.lnk . (.Microsoft Corporation - Age of Empires II DE.) C:\Program Files (x86)\Age of Empires II Definitive Edition\AoE2DE_s.exe =>.Microsoft®
O4 - GS\Desktop [Administrador]: Alan Wake.lnk . (...) C:\Games\Alan Wake Complete Collection\Alan Wake\alanwake.exe -locale=en =>.Remedy Entertainment Ltd.®
O4 - GS\Desktop [Administrador]: BH6.exe - Atalho.lnk . (.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) C:\Program Files (x86)\Resident Evil 6\BH6.exe =>.QLOC S.A.®
O4 - GS\Desktop [Administrador]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe [Unsigned]
O4 - GS\Desktop [Administrador]: Cheat Engine 6.6 (64-bit).lnk . (.Cheat Engine - Cheat Engine.) C:\Program Files (x86)\Cheat Engine 6.6\cheatengine-x86_64.exe =>.Cheat Engine®
O4 - GS\Desktop [Administrador]: Cheat Engine.lnk . (...) C:\Program Files\Cheat Engine 7.1\Cheat Engine.exe =>.Cheat Engine®
O4 - GS\Desktop [Administrador]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
O4 - GS\Desktop [Administrador]: EXCEL - Atalho.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE =>.Microsoft®
O4 - GS\Desktop [Administrador]: Google Anonimo.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe -incognito =>.Google LLC®
O4 - GS\Desktop [Administrador]: NZA.exe - Atalho.lnk . (...) C:\Program Files (x86)\Sniper Elite Nazi Zombie Army\bin\NZA.exe [Unsigned]
O4 - GS\Desktop [Administrador]: NZA2.exe - Atalho.lnk . (...) C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe [Unsigned]
O4 - GS\Desktop [Administrador]: POWERPNT - Atalho.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files (x86)\Microsoft Office\Office16\POWERPNT.EXE =>.Microsoft®
O4 - GS\Desktop [Administrador]: rerev.exe - Atalho.lnk . (...) C:\Program Files (x86)\Resident Evil Revelations\rerev.exe [Unsigned]
O4 - GS\Desktop [Administrador]: Resident Evil 6 v1.0 Plus 14 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil 6 v1.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Administrador]: Resident Evil HD Remaster.lnk . (...) C:\Program Files (x86)\Resident Evil HD Remaster\bhd.exe [Unsigned]
O4 - GS\Desktop [Administrador]: Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil Reve.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Administrador]: Resident Evil_Biohazard HD Remaster v1.0 Plus 16 Trainer Fixed.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil / Bi.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil_Biohazard HD Remaster v1.0 Plus 16 Trainer Fixed.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Administrador]: Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil_Reve.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Administrador]: The Evil Within.lnk . (.2014 Zenimax Media Inc. - The Evil Within.) C:\Games\The Evil Within\EvilWithin.exe [Unsigned]
O4 - GS\Desktop [Administrador]: unepic.exe - Atalho.lnk . (...) C:\Program Files (x86)\GOG Games\Unepic\unepic.exe [Unsigned]
O4 - GS\Desktop [Administrador]: WINWORD - Atalho.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE =>.Microsoft®
O4 - GS\Desktop [Administrador]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrador]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\Quicklaunch [Administrador]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\sendTo [Administrador]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Administrador]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Administrador]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - Transfere arquivos entre dispo.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\TaskBar [Administrador]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\TaskBar [Administrador]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --profile-directory=Default =>.Microsoft®
O4 - GS\TaskBar [Administrador]: qBittorrent.lnk . (...) C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O4 - GS\Programs [Administrador]: Gerenciador de áudio HD.lnk . (.Realtek Semiconductor - .) C:\Program Files (x86)\Realtek\Audio\HDA\RAVCpl64.exe [Unsigned] =>.Realtek Semiconductor
O4 - GS\Programs [Administrador]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Desktop [Convidado]: Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe - Atalho.lnk . (.3DMGAME - Age of Empires II Definitive Edition v1.0-B.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Convidado]: Age of Empires II Definitive Edition.lnk . (.Microsoft Corporation - Age of Empires II DE.) C:\Program Files (x86)\Age of Empires II Definitive Edition\AoE2DE_s.exe =>.Microsoft®
O4 - GS\Desktop [Convidado]: Alan Wake.lnk . (...) C:\Games\Alan Wake Complete Collection\Alan Wake\alanwake.exe -locale=en =>.Remedy Entertainment Ltd.®
O4 - GS\Desktop [Convidado]: BH6.exe - Atalho.lnk . (.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) C:\Program Files (x86)\Resident Evil 6\BH6.exe =>.QLOC S.A.®
O4 - GS\Desktop [Convidado]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe [Unsigned]
O4 - GS\Desktop [Convidado]: Cheat Engine 6.6 (64-bit).lnk . (.Cheat Engine - Cheat Engine.) C:\Program Files (x86)\Cheat Engine 6.6\cheatengine-x86_64.exe =>.Cheat Engine®
O4 - GS\Desktop [Convidado]: Cheat Engine.lnk . (...) C:\Program Files\Cheat Engine 7.1\Cheat Engine.exe =>.Cheat Engine®
O4 - GS\Desktop [Convidado]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
O4 - GS\Desktop [Convidado]: EXCEL - Atalho.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE =>.Microsoft®
O4 - GS\Desktop [Convidado]: Google Anonimo.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe -incognito =>.Google LLC®
O4 - GS\Desktop [Convidado]: NZA.exe - Atalho.lnk . (...) C:\Program Files (x86)\Sniper Elite Nazi Zombie Army\bin\NZA.exe [Unsigned]
O4 - GS\Desktop [Convidado]: NZA2.exe - Atalho.lnk . (...) C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe [Unsigned]
O4 - GS\Desktop [Convidado]: POWERPNT - Atalho.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files (x86)\Microsoft Office\Office16\POWERPNT.EXE =>.Microsoft®
O4 - GS\Desktop [Convidado]: rerev.exe - Atalho.lnk . (...) C:\Program Files (x86)\Resident Evil Revelations\rerev.exe [Unsigned]
O4 - GS\Desktop [Convidado]: Resident Evil 6 v1.0 Plus 14 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil 6 v1.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Convidado]: Resident Evil HD Remaster.lnk . (...) C:\Program Files (x86)\Resident Evil HD Remaster\bhd.exe [Unsigned]
O4 - GS\Desktop [Convidado]: Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil Reve.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Convidado]: Resident Evil_Biohazard HD Remaster v1.0 Plus 16 Trainer Fixed.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil / Bi.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil_Biohazard HD Remaster v1.0 Plus 16 Trainer Fixed.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Convidado]: Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil_Reve.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Convidado]: The Evil Within.lnk . (.2014 Zenimax Media Inc. - The Evil Within.) C:\Games\The Evil Within\EvilWithin.exe [Unsigned]
O4 - GS\Desktop [Convidado]: unepic.exe - Atalho.lnk . (...) C:\Program Files (x86)\GOG Games\Unepic\unepic.exe [Unsigned]
O4 - GS\Desktop [Convidado]: WINWORD - Atalho.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE =>.Microsoft®
O4 - GS\Desktop [Convidado]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\Quicklaunch [Convidado]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\Quicklaunch [Convidado]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\sendTo [Convidado]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Convidado]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Convidado]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - Transfere arquivos entre dispo.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\TaskBar [Convidado]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\TaskBar [Convidado]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --profile-directory=Default =>.Microsoft®
O4 - GS\TaskBar [Convidado]: qBittorrent.lnk . (...) C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O4 - GS\Programs [Convidado]: Gerenciador de áudio HD.lnk . (.Realtek Semiconductor - .) C:\Program Files (x86)\Realtek\Audio\HDA\RAVCpl64.exe [Unsigned] =>.Realtek Semiconductor
O4 - GS\Programs [Convidado]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Desktop [Ramon]: Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe - Atalho.lnk . (.3DMGAME - Age of Empires II Definitive Edition v1.0-B.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Ramon]: Age of Empires II Definitive Edition.lnk . (.Microsoft Corporation - Age of Empires II DE.) C:\Program Files (x86)\Age of Empires II Definitive Edition\AoE2DE_s.exe =>.Microsoft®
O4 - GS\Desktop [Ramon]: Alan Wake.lnk . (...) C:\Games\Alan Wake Complete Collection\Alan Wake\alanwake.exe -locale=en =>.Remedy Entertainment Ltd.®
O4 - GS\Desktop [Ramon]: BH6.exe - Atalho.lnk . (.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) C:\Program Files (x86)\Resident Evil 6\BH6.exe =>.QLOC S.A.®
O4 - GS\Desktop [Ramon]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe [Unsigned]
O4 - GS\Desktop [Ramon]: Cheat Engine 6.6 (64-bit).lnk . (.Cheat Engine - Cheat Engine.) C:\Program Files (x86)\Cheat Engine 6.6\cheatengine-x86_64.exe =>.Cheat Engine®
O4 - GS\Desktop [Ramon]: Cheat Engine.lnk . (...) C:\Program Files\Cheat Engine 7.1\Cheat Engine.exe =>.Cheat Engine®
O4 - GS\Desktop [Ramon]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
O4 - GS\Desktop [Ramon]: EXCEL - Atalho.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE =>.Microsoft®
O4 - GS\Desktop [Ramon]: Google Anonimo.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe -incognito =>.Google LLC®
O4 - GS\Desktop [Ramon]: NZA.exe - Atalho.lnk . (...) C:\Program Files (x86)\Sniper Elite Nazi Zombie Army\bin\NZA.exe [Unsigned]
O4 - GS\Desktop [Ramon]: NZA2.exe - Atalho.lnk . (...) C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe [Unsigned]
O4 - GS\Desktop [Ramon]: POWERPNT - Atalho.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files (x86)\Microsoft Office\Office16\POWERPNT.EXE =>.Microsoft®
O4 - GS\Desktop [Ramon]: rerev.exe - Atalho.lnk . (...) C:\Program Files (x86)\Resident Evil Revelations\rerev.exe [Unsigned]
O4 - GS\Desktop [Ramon]: Resident Evil 6 v1.0 Plus 14 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil 6 v1.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Ramon]: Resident Evil HD Remaster.lnk . (...) C:\Program Files (x86)\Resident Evil HD Remaster\bhd.exe [Unsigned]
O4 - GS\Desktop [Ramon]: Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil Reve.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Ramon]: Resident Evil_Biohazard HD Remaster v1.0 Plus 16 Trainer Fixed.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil / Bi.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil_Biohazard HD Remaster v1.0 Plus 16 Trainer Fixed.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Ramon]: Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe - Atalho.lnk . (.3DMGAME - FLiNG@3DMGAME Presents - Resident Evil_Reve.) C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe [Unsigned] =>.3DMGAME
O4 - GS\Desktop [Ramon]: The Evil Within.lnk . (.2014 Zenimax Media Inc. - The Evil Within.) C:\Games\The Evil Within\EvilWithin.exe [Unsigned]
O4 - GS\Desktop [Ramon]: unepic.exe - Atalho.lnk . (...) C:\Program Files (x86)\GOG Games\Unepic\unepic.exe [Unsigned]
O4 - GS\Desktop [Ramon]: WINWORD - Atalho.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE =>.Microsoft®
O4 - GS\Desktop [Ramon]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
O4 - GS\Quicklaunch [Ramon]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\Quicklaunch [Ramon]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\sendTo [Ramon]: Destinatário do fax.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Ramon]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
O4 - GS\sendTo [Ramon]: Transferência de Arquivo Bluetooth.LNK . (.Microsoft Corporation - Transfere arquivos entre dispo.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\TaskBar [Ramon]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\TaskBar [Ramon]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --profile-directory=Default =>.Microsoft®
O4 - GS\TaskBar [Ramon]: qBittorrent.lnk . (...) C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O4 - GS\Programs [Ramon]: Gerenciador de áudio HD.lnk . (.Realtek Semiconductor - .) C:\Program Files (x86)\Realtek\Audio\HDA\RAVCpl64.exe [Unsigned] =>.Realtek Semiconductor
O4 - GS\Programs [Ramon]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Inc.®
O4 - GS\CommonDesktop [Public]: Bitdefender Antivirus Free Edition.lnk . (.Bitdefender - Antivirus Free Edition.) C:\Program Files (x86)\Bitdefender\Antivirus Free Edition\gziface.exe [Unsigned] =>.BitDefender
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Software Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd®
O4 - GS\CommonDesktop [Public]: DAEMON Tools Lite.lnk . (.Disc Soft Ltd - DAEMON Tools Lite.) C:\Program Files\DAEMON Tools Lite\DTLauncher.exe =>.AVB Disc Soft, SIA®
O4 - GS\CommonDesktop [Public]: GOM Player.lnk . (.GOM & Company - GOM Player.) C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe {4F58FC05426CC4B65DBC0C2C2E3AF304}. =>.GOM & Company
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\CommonDesktop [Public]: GRID Autosport.lnk . (.Codemasters Software Company Limited - GRID Autosport Executable.) C:\Games\GRID Autosport\GRIDAutosport.exe [Unsigned] =>.Codemasters Software Company Limited
O4 - GS\CommonDesktop [Public]: Hollow Knight.lnk . (...) C:\Games\Hollow Knight\hollow_knight.exe [Unsigned]
O4 - GS\CommonDesktop [Public]: HP LJ M521 Scan.lnk . (.Hewlett-Packard Co. - HPScan.) C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\Bin\HPScan.exe =>.Hewlett Packard®
O4 - GS\CommonDesktop [Public]: Lifeless Planet.lnk . (...) C:\Program Files (x86)\KISS ltd\Lifeless Planet\LifelessPlanet.exe [Unsigned]
O4 - GS\CommonDesktop [Public]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: Picasa 3.lnk . (.Google Inc. - Picasa.) C:\Program Files (x86)\Google\Picasa3\Picasa3.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: qBittorrent.lnk . (...) C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O4 - GS\CommonDesktop [Public]: Resident Evil Revelations 2.lnk . (...) C:\Games\Resident Evil Revelations 2\rerev2.exe [Unsigned]
O4 - GS\CommonDesktop [Public]: Silent Hill - Homecoming.lnk . (...) C:\Program Files (x86)\Silent Hill - Homecoming\Bin\SilentHill.exe [Unsigned]
O4 - GS\CommonDesktop [Public]: The Witcher 2 - Assassins of Kings Enhanced Edition.lnk . (.CD Projekt RED - The Witcher 2 Launcher Application.) C:\Program Files (x86)\GOG.com\The Witcher 2 Enhanced Edition\Launcher.exe [Unsigned] =>.CD Projekt RED
O4 - GS\Programs [Public]: Gerenciador de áudio HD.lnk . (.Realtek Semiconductor - .) C:\Program Files (x86)\Realtek\Audio\HDA\RAVCpl64.exe [Unsigned] =>.Realtek Semiconductor
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloco de notas.) C:\WINDOWS\system32\notepad.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Conexão de Área de Trabalho Remota.) C:\WINDOWS\system32\mstsc.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Ferramenta de Captura.) C:\WINDOWS\system32\SnippingTool.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Gravador de Passos.) C:\WINDOWS\system32\psr.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Aplicativo Wordpad do Windows.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visualizador XPS.) C:\WINDOWS\system32\xpsrchvw.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Mapa de caracteres.) C:\WINDOWS\system32\charmap.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Inc.®
O4 - GS\ProgramsCommon [Public]: Excel 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe [Unsigned] =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: OneNote 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-0000-0000000FF1CE}\joticon.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Outlook 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-0000-0000000FF1CE}\outicon.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: PowerPoint 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-0000-0000000FF1CE}\pptico.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Publisher 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-0000-0000000FF1CE}\pubs.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Word 2016.lnk . (...) C:\Windows\Installer\{90160000-0011-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft®

---\\ Alteração Dominio/Clientes DNS (3) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.43.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{2cee45b1-fdb9-43ce-b842-75936eba262c}: DhcpNameServer = 192.168.43.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{c7639110-21ba-4a21-9266-c86849326a8f}: DhcpNameServer = 192.168.43.1 =>.Local IP Adress

---\\ Protocolo adicional (23) - 2s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para streaming de vídeo.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL =>.Microsoft®

---\\ Valor do Registo AppInit_DLLs e sub-chaves Winlogon Notify (1) - 1s
O20 - Winlogon : UserInit . (.Microsoft Corporation - Aplicativo de logon Userinit.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

---\\ Lista de chave explorando StartupApproved (18) - 0s
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:uTorrent
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:CCleaner Monitoring =>.Piriform Ltd
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]big_green.pngAEMON Tools Lite Automount =>.Disc Soft Ltd
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Google Update =>.Google Inc.
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:CCleaner Smart Cleaning =>.Piriform Ltd
[HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:uTorrent
[HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:CCleaner Monitoring =>.Piriform Ltd
[HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
[HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]big_green.pngAEMON Tools Lite Automount =>.Disc Soft Ltd
[HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Google Update =>.Google Inc.
[HKEY_USERS\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:CCleaner Smart Cleaning =>.Piriform Ltd
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:SecurityHealth =>.Microsoft Corporation
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:RTHDVCPL =>.Realtek Semiconductor Corp.
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]big_green.pngropbox =>.Dropbox Inc.
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]:SDTray =>.Microsoft Corporation
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]stick_out_tongue.pngSUAMain
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]:StatusAlerts

---\\ ASIC (ActiveSetup Installed Components) (7) - 2s
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitário de Instalação do Microsoft Windo.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitário de Instalação do Microsoft Windo.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google LLC - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\Installer\chrmstp.exe =>.Google LLC®
O40 - ASIC: Microsoft Edge [64Bits] - {9459C573-B17A-45AE-9F64-1857B5D58CEE} . (.Microsoft Corporation - Microsoft Edge Installer.) -- C:\Program Files (x86)\Microsoft\Edge\Application\87.0.664.57\Installer\setup.exe =>.Microsoft®

---\\ Software instalados (84) - 33s
O42 - Logiciel: 64 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM][64Bits] -- {3138F992-045B-4F55-825C-53B231E647CA} [Unsigned] =>.Hewlett-Packard (Hidden)
O42 - Logiciel: Adobe Acrobat Reader DC - Português - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1046-7B44-AC0F074E4100} [Unsigned] =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824406920} [Unsigned] =>.Adobe Systems Incorporated (Hidden)
O42 - Logiciel: Age of Empires II Definitive Edition - (.Microsoft Corporation.) [HKLM][64Bits] -- Age of Empires II Definitive Edition_is1 [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Alan Wake Complete Collection versão 1.06.17.0155 - (.Remedy Entertainment.) [HKLM][64Bits] -- {2DE8F160-BBFF-445B-8B8E-4092A1C106DA}_is1 [Unsigned]
O42 - Logiciel: AxCrypt 2.1.1481.0 - (.AxCrypt AB.) [HKLM][64Bits] -- {0E1E3ADA-7669-6F26-5005-B7B48579F531} [Unsigned] =>.AxCrypt AB (Hidden)
O42 - Logiciel: AxCrypt 2.1.1481.0 - (.AxCrypt AB.) [HKLM][64Bits] -- {18db8d8e-e8a9-4911-a0bb-978f5341daeb} =>.AxCrypt AB®
O42 - Logiciel: Bitdefender Antivirus Free Edition - (.Bitdefender.) [HKLM][64Bits] -- BitDefender Gonzales =>.Bitdefender SRL®
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Software Ltd®
O42 - Logiciel: CDisplay 1.8 - (.dvd8n.) [HKLM][64Bits] -- CDisplay_is1 [Unsigned] =>.dvd8n
O42 - Logiciel: Cheat Engine 6.6 - (.Cheat Engine.) [HKLM][64Bits] -- Cheat Engine 6.6_is1 =>.Cheat Engine®
O42 - Logiciel: Cheat Engine 7.1 - (.Cheat Engine.) [HKLM][64Bits] -- Cheat Engine_is1 =>.Cheat Engine®
O42 - Logiciel: DAEMON Tools Lite - (.Disc Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite =>.AVB Disc Soft, SIA®
O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKLM][64Bits] -- Dropbox =>.Dropbox, Inc®
O42 - Logiciel: Dropbox Update Helper - (.Dropbox, Inc..) [HKLM][64Bits] -- {099218A5-A723-43DC-8DB5-6173656A1E94} [Unsigned] =>.Dropbox, Inc. (Hidden)
O42 - Logiciel: ffdshow v1.3.4532 [2014-07-17] - (.Open Source.) [HKLM][64Bits] -- ffdshow_is1 [Unsigned] =>.Open source
O42 - Logiciel: GOM Player - (.GOM & Company.) [HKLM][64Bits] -- GOM Player {4F58FC05426CC4B65DBC0C2C2E3AF304}. =>.GOM & Company
O42 - Logiciel: Google Chrome - (.Google LLC.) [HKLM][64Bits] -- Google Chrome =>.Google LLC®
O42 - Logiciel: Google Photos Backup - (.Google, Inc..) [HKCU][64Bits] -- Google Photos Backup [Unsigned] =>.Google, Inc.
O42 - Logiciel: Google Update Helper - (.Google LLC.) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} [Unsigned] =>.Google LLC (Hidden)
O42 - Logiciel: GRID Autosport MULTi9 - ElAmigos versão 1.0.103.1840 u10 - (.Codemasters.) [HKLM][64Bits] -- {17BDFEA1-3A20-4BF1-9A29-5002F791E0AE}_is1 [Unsigned] =>.Codemasters
O42 - Logiciel: Herramientas de corrección de Microsoft Office 2016: español - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0C0A-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Hollow Knight MULTi2 - ElAmigos versão 1.4.3.2 - (.Team Cherry.) [HKLM][64Bits] -- {1CD3BBBF-DF40-4A2B-9580-F1021E575C2C}_is1 [Unsigned]
O42 - Logiciel: HP LaserJet Pro MFP M521 - (.Hewlett-Packard.) [HKLM][64Bits] -- {8c0c6b8e-5f52-48bc-afe5-e43403a7d16e} =>.Hewlett-Packard Company®
O42 - Logiciel: HP LaserJet Pro MFP M521 Fax - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {AE990E78-80BC-4799-92C9-2F38CD9E2DC1} [Unsigned] =>.Hewlett-Packard Co. (Hidden)
O42 - Logiciel: HP LaserJet Pro MFP M521 Fax - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {FB5F3C7F-0E18-456D-B3C4-0B38FA0DE225} [Unsigned] =>.Hewlett-Packard Co. (Hidden)
O42 - Logiciel: HP LaserJet Pro MFP M521 Fax Driver - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {247F5986-4AAE-4381-A3DE-9C9ED11AD658} [Unsigned] =>.Hewlett-Packard Co. (Hidden)
O42 - Logiciel: HP LaserJet Pro MFP M521 HP Device Toolbox - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {92E58B03-D72B-4D4E-A389-573853836148} [Unsigned] =>.Hewlett-Packard Co. (Hidden)
O42 - Logiciel: HP LJ M521 Scan HP Scan - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {2E6ABD7C-5EAE-4D70-A90C-5DCDADF12983} [Unsigned] =>.Hewlett-Packard Co. (Hidden)
O42 - Logiciel: HP Product FWUpdater - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {2E55F5FF-EC0F-4DF9-A994-4A0251491BE5} [Unsigned] =>.Hewlett-Packard Company (Hidden)
O42 - Logiciel: HP Unified IO - (.HP.) [HKLM][64Bits] -- {5C76ED0D-0F6F-4985-8B34-F9AE7834848F} [Unsigned] =>.HP (Hidden)
O42 - Logiciel: HP Unified IO - (.HP.) [HKLM][64Bits] -- {F1390872-2500-4408-A46C-CD16C960C661} [Unsigned] =>.HP (Hidden)
O42 - Logiciel: hpbDSService - (.Hewlett-Packard.) [HKLM][64Bits] -- {62022DCB-BA92-4EC2-AE03-9B946E4DBF12} [Unsigned] =>.Hewlett-Packard (Hidden)
O42 - Logiciel: hpbM521DSService - (.Hewlett-Packard.) [HKLM][64Bits] -- {B8CC3415-129F-4DB2-A5C4-4AF911A6EC68} [Unsigned] =>.Hewlett-Packard (Hidden)
O42 - Logiciel: hppLaserJetService - (.Hewlett-Packard.) [HKLM][64Bits] -- {2521609E-E23E-4F13-88B1-F8EA8CD5E1FD} [Unsigned] =>.Hewlett-Packard (Hidden)
O42 - Logiciel: hppM521LaserJetService - (.Hewlett-Packard.) [HKLM][64Bits] -- {5DE8C170-B718-4BCD-9395-B3B3EBEEFA21} [Unsigned] =>.Hewlett-Packard (Hidden)
O42 - Logiciel: hpStatusAlerts - (.Hewlett Packard.) [HKLM][64Bits] -- {FA449D99-12FC-41ED-94B3-58032C8C3527} [Unsigned] =>.Hewlett Packard (Hidden)
O42 - Logiciel: hpStatusAlertsM521 - (.Hewlett-Packard.) [HKLM][64Bits] -- {1958120F-5E52-4821-A25A-F7EACC1E9457} [Unsigned] =>.Hewlett-Packard (Hidden)
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel(R) pGFX®
O42 - Logiciel: Lifeless Planet - (..) [HKLM][64Bits] -- Lifeless Planet_is1 [Unsigned]
O42 - Logiciel: Microsoft Access MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0015-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft DCF MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0090-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Edge - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge =>.Microsoft®
O42 - Logiciel: Microsoft Edge Update - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge Update [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0016-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Games for Windows - LIVE Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {F2508213-9989-4E85-A078-72BE483917EF} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Games for Windows Marketplace - (.Microsoft Corporation.) [HKLM][64Bits] -- {4CB0307C-565E-4441-86BE-0DF2E4FB828C} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Groove MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00BA-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtensio - (.Microsoft Corporation.) [HKLM][64Bits] -- {B0169E83-757B-EF66-E2F0-391944D785BC} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft InfoPath MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0044-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office 64-bit Components 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office OSM MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00E1-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office OSM UX MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00E2-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Professional Plus 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Professional Plus 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office16.PROPLUS =>.Microsoft®
O42 - Logiciel: Microsoft Office Proofing (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-002C-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Proofing Tools 2016 - English - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-002A-0416-1000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Shared MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-006E-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft®
O42 - Logiciel: Microsoft OneNote MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00A1-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Outlook MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001A-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft PowerPoint MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0018-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Publisher MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0019-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Skype for Business MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-012B-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Update Health Tools - (.Microsoft Corporation.) [HKLM][64Bits] -- {0BCA8FBE-0C1C-4C65-98A3-5D34AAF41737} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 - (.Microsoft Corporation.) [HKLM][64Bits] -- {196BB40D-1578-3D01-B289-BEFC77A11A1E} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Word MUI (Portuguese (Brazil)) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001B-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Mozilla Firefox 46.0.1 (x86 pt-BR) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 46.0.1 (x86 pt-BR) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService [Unsigned] =>.Mozilla
O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM][64Bits] -- {3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA} [Unsigned] =>.NVIDIA Corporation
O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM][64Bits] -- Picasa 3 =>.Google Inc®
O42 - Logiciel: qBittorrent 4.3.2 - (.The qBittorrent project.) [HKLM][64Bits] -- qBittorrent [Unsigned] =>.The qBittorrent project
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Resident Evil 6 version 1 - (..) [HKLM][64Bits] -- UmVzaWRlbnQgRXZpbCA2_is1 [Unsigned]
O42 - Logiciel: Resident Evil HD Remaster - (..) [HKLM][64Bits] -- Resident Evil HD Remaster_is1 [Unsigned]
O42 - Logiciel: Resident Evil Revelations 2 versão 5.0 u17 - (.Capcom.) [HKLM][64Bits] -- {F88D9F7A-946D-418E-929F-1F4835AF8F98}_is1 [Unsigned] =>.CAPCOM
O42 - Logiciel: Revisores de Texto do Microsoft Office 2016 – Português (Brasil) - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0416-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Revo Uninstaller 2.1.0 - (.VS Revo Group, Ltd..) [HKLM][64Bits] -- {A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1 [Unsigned] =>.VS Revo Group, Ltd.
O42 - Logiciel: Silent Hill - Homecoming version 1.0 - (.Konami.) [HKLM][64Bits] -- Silent Hill - Homecoming_is1 [Unsigned] =>.Konami
O42 - Logiciel: The Evil Within - (.R.G. Mechanics, spider91.) [HKLM][64Bits] -- The Evil Within_R.G. Mechanics_is1 [Unsigned] =>.R.G. Mechanics, spider91
O42 - Logiciel: The Witcher 2 - Assassins of Kings Enhanced Edition - (.GOG.com.) [HKLM][64Bits] -- The Witcher 2 - Assassins of Kings Enhanced Edition_is1 [Unsigned] =>.GOG.com
O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4023057) - (.Microsoft Corporation.) [HKLM][64Bits] -- {32DC821E-4A7D-4878-BEE8-337FA153D7F2} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: WinRAR 5.40 beta 2 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®

---\\ HKCU & HKLM Software Keys (176) - 34s
HKLM\SOFTWARE\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\AVC3 =>.Bitdefender
HKLM\SOFTWARE\AxCrypt =>.AxCrypt
HKLM\SOFTWARE\Bitdefender =>.Bitdefender
HKLM\SOFTWARE\DefaultUserEnvironment =>.Microsoft Corporation
HKLM\SOFTWARE\Disc Soft =>.Disc Soft
HKLM\SOFTWARE\Dolby =>.Dolby
HKLM\SOFTWARE\DTS =>.Creative Technology
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Khronos =>.Khronos
HKLM\SOFTWARE\Knowles =>.Knowles Electronics
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Nahimic =>.Nahimic
HKLM\SOFTWARE\Nuance =>.Nuance
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\OEM =>.OEM
HKLM\SOFTWARE\OpenSSH =>.OpenBSD
HKLM\SOFTWARE\Partner =>.Google Inc.
HKLM\SOFTWARE\Piriform =>.Piriform
HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\SonicFocus =>.Sonic Focus
HKLM\SOFTWARE\SoundResearch =>.Sound Research
HKLM\SOFTWARE\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\tools
HKLM\SOFTWARE\vSnapshot
HKLM\SOFTWARE\vSnapshotEncodeTools
HKLM\SOFTWARE\Waves Audio =>.Waves Audio
HKLM\SOFTWARE\Windows =>.Microsoft Corporation
HKLM\SOFTWARE\WinRAR =>.WinRAR
HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Yamaha APO =>.Yamaha Corp.
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\WOW6432Node\ARTDINK
HKLM\SOFTWARE\WOW6432Node\CD Projekt RED =>.CD Projekt RED
HKLM\SOFTWARE\WOW6432Node\DivXNetworks =>.DivXNetworks
HKLM\SOFTWARE\WOW6432Node\Dropbox =>.Dropbox
HKLM\SOFTWARE\WOW6432Node\DropboxUpdate =>.Dropbox Inc.
HKLM\SOFTWARE\WOW6432Node\GameVicio =>.GameVicio
HKLM\SOFTWARE\WOW6432Node\Gili File Lock =>.GiliSoft International LLC.
HKLM\SOFTWARE\WOW6432Node\GNU =>.GNU
HKLM\SOFTWARE\WOW6432Node\GOG.com =>.GOG.com
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\GRETECH =>.Gretech
HKLM\SOFTWARE\WOW6432Node\Hewlett-Packard =>.Hewlett-Packard
HKLM\SOFTWARE\WOW6432Node\InstallShield =>.InstallShield
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\Panda Software =>.Panda Software
HKLM\SOFTWARE\WOW6432Node\qBittorrent =>.uTorrent (P2P)
HKLM\SOFTWARE\WOW6432Node\Safer Networking Limited =>.Safer Networking Limited
HKLM\SOFTWARE\WOW6432Node\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\WOW6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\XLiveEmulator
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKCU\SOFTWARE\AxCrypt =>.AxCrypt
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\Bitdefender =>.Bitdefender
HKCU\SOFTWARE\CD Projekt RED =>.CD Projekt RED
HKCU\SOFTWARE\CDisplay =>.David Ayton
HKCU\SOFTWARE\Cheat Engine =>.Dark Byte
HKCU\SOFTWARE\Cheat Evolution
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Disc Soft =>.Disc Soft
HKCU\SOFTWARE\Dropbox =>.Dropbox
HKCU\SOFTWARE\DropboxUpdate =>.Dropbox Inc.
HKCU\SOFTWARE\DSS =>.DSS Software
HKCU\SOFTWARE\ElAmigos =>.ElAmigos
HKCU\SOFTWARE\EMU =>.Games Software
HKCU\SOFTWARE\FearlessRevolution
HKCU\SOFTWARE\FLT =>.FLT Software
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\GOG.com =>.GOG.com
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\GRETECH =>.Gretech
HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKCU\SOFTWARE\IM =>.Legitimate
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\MPC-HC =>.MPC-HC Team
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\PopCap =>.Popcap Games
HKCU\SOFTWARE\profession
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Safer Networking Limited =>.Safer Networking Limited
HKCU\SOFTWARE\SKS =>.SKS Software
HKCU\SOFTWARE\Stage 2 Studios
HKCU\SOFTWARE\Team Cherry
HKCU\SOFTWARE\Tribo Gamer
HKCU\SOFTWARE\Unity =>.Unity
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\VS Revo Group =>.VS Revo Group
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\Baidu =>.Baidu
HKU\.DEFAULT\SOFTWARE\Bitdefender =>.Bitdefender
HKU\.DEFAULT\SOFTWARE\Dropbox =>.Dropbox
HKU\.DEFAULT\SOFTWARE\Google =>.Google
HKU\.DEFAULT\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKU\.DEFAULT\SOFTWARE\Mozilla =>.Mozilla
HKU\.DEFAULT\SOFTWARE\Netscape =>.Netscape
HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform
HKU\.DEFAULT\SOFTWARE\profession
HKU\.DEFAULT\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\Safer Networking Limited =>.Safer Networking Limited
HKU\.DEFAULT\SOFTWARE\SetID =>.Bitdefender
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Adobe =>.Adobe
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AxCrypt =>.AxCrypt
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Baixaki =>.Baixaki
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Bitdefender =>.Bitdefender
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\CD Projekt RED =>.CD Projekt RED
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\CDisplay =>.David Ayton
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Cheat Engine =>.Dark Byte
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Cheat Evolution
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Chromium =>.Chromium
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Disc Soft =>.Disc Soft
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Dropbox =>.Dropbox
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\DropboxUpdate =>.Dropbox Inc.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\DSS =>.DSS Software
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\ElAmigos =>.ElAmigos
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\EMU =>.Games Software
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\FearlessRevolution
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\FLT =>.FLT Software
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\GNU =>.GNU
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\GOG.com =>.GOG.com
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Google =>.Google
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\GRETECH =>.Gretech
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\IM =>.Legitimate
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Intel =>.Intel
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Macromedia =>.Macromedia
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\MPC-HC =>.MPC-HC Team
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Netscape =>.Netscape
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Piriform =>.Piriform
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\PopCap =>.Popcap Games
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\profession
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Safer Networking Limited =>.Safer Networking Limited
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\SKS =>.SKS Software
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Stage 2 Studios
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Team Cherry
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Tribo Gamer
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Unity =>.Unity
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Valve =>.Valve
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\VS Revo Group =>.VS Revo Group
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\WinRAR =>.WinRAR
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\ZHP =>.Nicolas Coolman

---\\ Packages (6) - 0s
C:\Program Files (x86)\WindowsApps\4DF9E0F8.Netflix_6.95.602.0_x64__mcm4njqhnhss8 - (.Netflix.) [][Netflix] =>Netflix
C:\Program Files (x86)\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w - (.Autodesk Inc..) [][Autodesk SketchBook] =>Autodesk Inc.
C:\Program Files (x86)\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm - (.Twitter Inc..) [][Twitter] =>Twitter Inc.
C:\Program Files (x86)\WindowsApps\AD2F1837.HPPrinterControl_105.1.623.0_x64__v10z8vjag6ke6 - (.Hewlett-Packard.) [][HP Smart] =>Hewlett-Packard
C:\Program Files (x86)\WindowsApps\king.com.CandyCrushSodaSaga_1.151.300.0_x86__kgqvnymyfvs32 - (.king.com.) [][Candy Crush Soda Saga] =>king.com
C:\Program Files (x86)\WindowsApps\MaciejStruzyna.BraveFurries_1.1.0.0_x86__asmb306w62ar2 - (.Maciej Struzyna.) [][Brave Furries]

---\\ Conteúdo das pastas Programs (269) - 85s
O43 - CFD: 31/05/2016 - [0] SHD -- C:\Program Files\Arquivos Comuns =>.Microsoft Corporation
O43 - CFD: 07/12/2016 - [] D -- C:\Program Files\AxCrypt =>.AxCrypt
O43 - CFD: 12/08/2016 - [] D -- C:\Program Files\Bitdefender =>.Bitdefender
O43 - CFD: 15/01/2021 - [] AD -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 09/12/2020 - [] D -- C:\Program Files\Cheat Engine 7.1 =>.Dark Byte
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 25/10/2018 - [] D -- C:\Program Files\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 07/06/2016 - [] D -- C:\Program Files\HP =>.Hewlett-Packard
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 08/05/2020 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 09/12/2020 - [] D -- C:\Program Files\Microsoft Update Health Tools =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\Program Files\ModifiableWindowsApps =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 13/01/2021 - [] D -- C:\Program Files\qBittorrent [Unsigned]
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 29/11/2019 - [] D -- C:\Program Files\rempl =>.Microsoft Corporation
O43 - CFD: 13/02/2016 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 24/06/2020 - [] AD -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 31/08/2016 - [] D -- C:\Program Files\VS Revo Group =>.VS Revo Group
O43 - CFD: 08/05/2020 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 08/05/2020 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 01/07/2020 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 01/07/2020 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 09/12/2020 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 07/06/2016 - [] AD -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 07/06/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Inc.®
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Age of Empires II Definitive Edition =>.Microsoft®
O43 - CFD: 01/09/2016 - [] D -- C:\Program Files (x86)\Capcom =>.CAPCOM
O43 - CFD: 01/02/2017 - [] D -- C:\Program Files (x86)\CDisplay [Unsigned]
O43 - CFD: 18/05/2017 - [] AD -- C:\Program Files (x86)\Cheat Engine 6.6 =>.Dark Byte
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 12/12/2019 - [] D -- C:\Program Files (x86)\Dropbox =>.Dropbox, Inc®
O43 - CFD: 24/06/2020 - [] D -- C:\Program Files (x86)\ffdshow =>.Open Source
O43 - CFD: 02/12/2020 - [] D -- C:\Program Files (x86)\GameVicio [Unsigned]
O43 - CFD: 30/09/2020 - [] D -- C:\Program Files (x86)\GOG Games [Unsigned]
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files (x86)\GOG.com =>.GOG.com
O43 - CFD: 07/11/2019 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 12/08/2016 - [] D -- C:\Program Files (x86)\GRETECH {4F58FC05426CC4B65DBC0C2C2E3AF304}. =>.Gretech
O43 - CFD: 07/06/2016 - [] D -- C:\Program Files (x86)\HP =>.Hewlett-Packard
O43 - CFD: 13/10/2016 - [0] D -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 07/06/2016 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 08/05/2020 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 06/06/2017 - [] D -- C:\Program Files (x86)\KISS ltd [Unsigned]
O43 - CFD: 04/12/2017 - [0] AD -- C:\Program Files (x86)\Malwarebytes Anti-Malware =>.Malwarebytes
O43 - CFD: 09/12/2020 - [] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 25/08/2016 - [] D -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [] AD -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [] D -- C:\Program Files (x86)\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 07/06/2016 - [] AD -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 07/06/2016 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 06/10/2016 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 24/10/2016 - [] AD -- C:\Program Files (x86)\Resident Evil 6 =>.Games Software
O43 - CFD: 16/08/2016 - [] AD -- C:\Program Files (x86)\Resident Evil HD Remaster =>.Games Software
O43 - CFD: 07/09/2018 - [] D -- C:\Program Files (x86)\Resident Evil Revelations =>.Games Software
O43 - CFD: 02/12/2020 - [] D -- C:\Program Files (x86)\Silent Hill - Homecoming [Unsigned]
O43 - CFD: 17/04/2020 - [] D -- C:\Program Files (x86)\Sniper Elite Nazi Zombie Army =>.Games Software
O43 - CFD: 25/04/2020 - [] D -- C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2 =>.Games Software
O43 - CFD: 14/05/2017 - [0] D -- C:\Program Files (x86)\TEW
O43 - CFD: 21/11/2017 - [] D -- C:\Program Files (x86)\Tribo Gamer [Unsigned]
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 01/07/2020 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 01/07/2020 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 01/07/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 01/07/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 29/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alan Wake Complete Collection
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AxCrypt =>.AxCrypt
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplay
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.6 =>.Dark Byte
O43 - CFD: 16/07/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 7.1 =>.Dark Byte
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 12/12/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox =>.Dropbox
O43 - CFD: 28/11/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office 2016 =>.Microsoft Corporation
O43 - CFD: 24/06/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow =>.Open Source
O43 - CFD: 19/12/2020 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com =>.GOG.com
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player =>.Gretech Corporation
O43 - CFD: 12/12/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GRID Autosport
O43 - CFD: 09/12/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hollow Knight
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KISS ltd
O43 - CFD: 19/03/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 =>.Google Inc.
O43 - CFD: 19/11/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics =>.R.G. Mechanics
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resident Evil HD Remaster =>.Games Software
O43 - CFD: 12/12/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller =>.VS Revo Group
O43 - CFD: 02/12/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Silent Hill - Homecoming
O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 08/05/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 13/02/2016 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology
O43 - CFD: 12/12/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 07/06/2016 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 17/08/2016 - [] D -- C:\ProgramData\bdch =>.Softwin
O43 - CFD: 28/12/2016 - [] AD -- C:\ProgramData\Bluestacks =>.BlueStack Systems, Inc.
O43 - CFD: 26/12/2016 - [0] D -- C:\ProgramData\BlueStacksSetup =>.BlueStack Systems, Inc.
O43 - CFD: 12/12/2019 - [] D -- C:\ProgramData\Codemasters =>.Codemasters
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [0] SHD -- C:\ProgramData\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 25/10/2018 - [] D -- C:\ProgramData\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 28/11/2019 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [0] SHD -- C:\ProgramData\Documentos =>.Microsoft Corporation
O43 - CFD: 27/09/2016 - [] D -- C:\ProgramData\Dropbox =>.Dropbox
O43 - CFD: 07/12/2016 - [0] D -- C:\ProgramData\GiliSoft =>.GiliSoft International LLC.
O43 - CFD: 12/08/2016 - [] D -- C:\ProgramData\GRETECH =>.Gretech
O43 - CFD: 29/09/2016 - [] D -- C:\ProgramData\GZ
O43 - CFD: 07/06/2016 - [] D -- C:\ProgramData\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 01/09/2016 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard
O43 - CFD: 01/09/2016 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 31/05/2016 - [0] SHD -- C:\ProgramData\Menu Iniciar =>.Microsoft Corporation
O43 - CFD: 09/12/2020 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 31/05/2016 - [0] SHD -- C:\ProgramData\Modelos =>.Microsoft Corporation
O43 - CFD: 26/09/2016 - [] D -- C:\ProgramData\Orbit =>.Orbit
O43 - CFD: 07/12/2016 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\Packages =>.Microsoft Corporation
O43 - CFD: 11/08/2016 - [] D -- C:\ProgramData\Panda Security =>.Panda Security
O43 - CFD: 22/09/2020 - [] D -- C:\ProgramData\PopCap Games =>.PopCap Games
O43 - CFD: 15/01/2021 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 08/05/2020 - [0] D -- C:\ProgramData\ssh =>.Microsoft Corporation
O43 - CFD: 12/12/2019 - [] D -- C:\ProgramData\Steam =>.Steam Games
O43 - CFD: 11/07/2017 - [] D -- C:\ProgramData\tools
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 07/06/2016 - [] AD -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 31/05/2016 - [] AD -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 06/10/2016 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard =>.Seagate
O43 - CFD: 29/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 11/02/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Cheat Happens
O43 - CFD: 22/06/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 27/09/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Dropbox =>.Dropbox
O43 - CFD: 12/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\GRETECH =>.Gretech
O43 - CFD: 11/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Hewlett-Packard Company =>.Hewlett-Packard Company
O43 - CFD: 16/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 28/11/2019 - [] SD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 06/12/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Mobon
O43 - CFD: 26/12/2016 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 01/07/2020 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\MPC-HC =>.MPC-HC Team
O43 - CFD: 28/03/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\poclbm
O43 - CFD: 14/01/2021 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\qBittorrent
O43 - CFD: 12/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\QuickScan =>.Bitdefender
O43 - CFD: 05/12/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Skype =>.Skype
O43 - CFD: 16/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Steam =>.Steam Games
O43 - CFD: 19/11/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\The Evil Within
O43 - CFD: 11/07/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Tools
O43 - CFD: 05/10/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\unepic
O43 - CFD: 16/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 15/01/2021 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 11/08/2016 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\ActiveSync =>.Microsoft Corporation
O43 - CFD: 13/12/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Adobe =>.Adobe
O43 - CFD: 12/01/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\AxCrypt =>.AxCrypt
O43 - CFD: 25/10/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\CAPCOM =>.CAPCOM
O43 - CFD: 29/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\CEF =>.CEF
O43 - CFD: 14/03/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 02/11/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\D3DSCache =>.Legitimate
O43 - CFD: 28/11/2019 - [0] SHD -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 09/06/2017 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\DBG =>.DBG
O43 - CFD: 14/01/2021 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 25/10/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Disc_Soft_Ltd =>.Disc Soft Ltd
O43 - CFD: 05/04/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Dropbox =>.Dropbox
O43 - CFD: 16/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 25/04/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\EMU =>.Games Software
O43 - CFD: 28/11/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\FLiNGTrainer
O43 - CFD: 07/09/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\FLT =>.FLT Software
O43 - CFD: 09/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\GOG.com =>.GOG.com
O43 - CFD: 13/01/2021 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Google =>.Google
O43 - CFD: 28/11/2019 - [0] SHD -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Histórico =>.Microsoft Corporation
O43 - CFD: 17/08/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\HP =>.Hewlett-Packard
O43 - CFD: 01/09/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Intel =>.Intel Corporation
O43 - CFD: 26/12/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 22/01/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\mbam =>.Malwarebytes
O43 - CFD: 22/01/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\mbamtray =>.Malwarebytes
O43 - CFD: 24/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 22/09/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 28/03/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 12/08/2016 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 21/09/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Ori and the Blind Forest DE
O43 - CFD: 09/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 12/08/2016 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 04/12/2019 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\PlaceholderTileLogoFolder =>.Microsoft Corporation
O43 - CFD: 09/11/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\plitch-updater
O43 - CFD: 03/12/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 25/10/2018 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 08/05/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\qBittorrent
O43 - CFD: 06/06/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\SKIDROW =>.SKIDROW
O43 - CFD: 17/04/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Sniper Elite Nazi Zombie Army =>.Games Software
O43 - CFD: 25/04/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Sniper Elite Nazi Zombie Army 2 =>.Games Software
O43 - CFD: 15/01/2021 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [0] SHD -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\The Witcher 2 =>.Atari Inc
O43 - CFD: 10/12/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 26/12/2016 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Troubleshooter =>.Unknown
O43 - CFD: 24/06/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 13/01/2021 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 12/08/2016 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 03/12/2016 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Local\Programs\Google =>.Google
O43 - CFD: 16/12/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\LocalLow\Adobe =>.Adobe
O43 - CFD: 04/09/2018 - [] SD -- C:\Users\Ramon.NOTEBOOK\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 02/02/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\LocalLow\SKS
O43 - CFD: 06/06/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\LocalLow\Stage 2 Studios
O43 - CFD: 09/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\LocalLow\Team Cherry
O43 - CFD: 14/01/2021 - [0] D -- C:\Users\Ramon.NOTEBOOK\AppData\LocalLow\Temp =>.Microsoft Corporation
O43 - CFD: 28/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\HK
O43 - CFD: 19/11/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\Marco
O43 - CFD: 30/12/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\MPC-HC.1.7.13.x86
O43 - CFD: 22/09/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\Plants
O43 - CFD: 23/09/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\Q
O43 - CFD: 24/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\Receitas NET
O43 - CFD: 15/01/2021 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\TEW
O43 - CFD: 25/04/2017 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\The.Shining.1980.US.1080p.BluRay.H264.AAC-RARBG
O43 - CFD: 03/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's
O43 - CFD: 29/11/2019 - [] D -- C:\Users\Public\Desktop\Alan Wake Complete Collection
O43 - CFD: 28/11/2019 - [] RD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] RD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] RD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 02/12/2020 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameVicio
O43 - CFD: 28/11/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Photos Backup =>.Google Inc.
O43 - CFD: 19/03/2019 - [] D -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [] RD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\Users\Ramon.NOTEBOOK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 08/09/2016 - [0] SHD -- C:\Users\Default\AppData\Local\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 08/09/2016 - [0] SHD -- C:\Users\Default\AppData\Local\Histórico =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/09/2016 - [0] SHD -- C:\Users\Default User\AppData\Local\Dados de Aplicativos =>.Microsoft Corporation
O43 - CFD: 08/09/2016 - [0] SHD -- C:\Users\Default User\AppData\Local\Histórico =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 28/11/2019 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 12/12/2019 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Adobe =>.Adobe
O43 - CFD: 12/12/2019 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Dropbox =>.Dropbox
O43 - CFD: 03/12/2019 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 12/12/2019 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 12/12/2019 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Dropbox =>.Dropbox
O43 - CFD: 12/12/2019 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation

---\\ ShellIconOverlayIdentifiers (SIOI) (15) - 1s
O106 - SIOI: DropboxExt1 Class [ DropboxExt01] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt7 Class [ DropboxExt02] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt9 Class [ DropboxExt03] - {FB314EE1-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt3 Class [ DropboxExt04] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt2 Class [ DropboxExt05] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt4 Class [ DropboxExt06] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt5 Class [ DropboxExt07] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt8 Class [ DropboxExt08] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt10 Class [ DropboxExt09] - {FB314EE2-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt6 Class [ DropboxExt10] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O106 - SIOI: [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®
O106 - SIOI: [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®
O106 - SIOI: [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®
O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL de Extensão do Shell do Armazenamento A.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - Interface de usuário de cache do cliente.) -- C:\WINDOWS\System32\cscui.dll [Unsigned] =>.Microsoft Corporation

---\\ Search Context Menu Handlers (SCMH) (25) - 2s
O108 - CMH1: Gonzales [64Bits] - {A50F8401-953F-4C11-8B77-1278C6C7C3F4} . (.Bitdefender - Gonzales Shell Extension.) -- C:\Program Files\Bitdefender\Antivirus Free Edition\GzShellIntegration.dll =>.Bitdefender SRL®
O108 - CMH1: ModernSharing [64Bits] - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH1: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH2: DropboxExt [64Bits] - {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} . (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Interface de usuário de cache do cliente.) -- C:\WINDOWS\System32\cscui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH4: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH5: DropboxExt [64Bits] - {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} . (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc®
O108 - CMH5: igfxDTCM [64Bits] - {9B5F5829-A529-4B12-814A-E81BCB8D93FC} . (.Intel Corporation - igfxDTCM Module.) -- C:\WINDOWS\system32\igfxDTCM.dll [Unsigned] =>.Intel Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH5: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH6: Gonzales [64Bits] - {A50F8401-953F-4C11-8B77-1278C6C7C3F4} . (.Bitdefender - Gonzales Shell Extension.) -- C:\Program Files\Bitdefender\Antivirus Free Edition\GzShellIntegration.dll =>.Bitdefender SRL®
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Interface de usuário de cache do cliente.) -- C:\WINDOWS\System32\cscui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - Resolvedor de Aplicativos.) -- C:\Windows\System32\appresolver.dll =>.Microsoft®
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL de Extensão do Shell do Armazenamento A.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensões do Shell para compartilhamento.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation

---\\ Image File Execution Options (17) - 4s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Módulo de Instalação de Driver.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Utilitário de Instalação Autônoma do IE 7.0.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Console de Gerenciamento Microsoft.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\MRT.exe - (.Microsoft Corporation - Ferramentas de Remoção de Software Mal-Inte.) [CFGOptions\\1] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Host de Aplicativo HTML da Microsoft(R).) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Host do Windows Presentation Foundation.) [MitigationOptions\\1118481] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processo de host do Windows (Rundll32).) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Aplicativo de subsistema de spooler.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processo de Host para Serviços do Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation

---\\ Lista dos drivers do sistema (441) - 31s
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\WINDOWS\System32\drivers\1394ohci.sys [264704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107528] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:16:42 A . (.Microsoft Corporation - ACPI Driver for NT.) -- C:\WINDOWS\System32\drivers\acpi.sys [804664] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - ACPI Devices Driver.) -- C:\WINDOWS\System32\drivers\AcpiDev.sys [20992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - ACPIEx Driver.) -- C:\WINDOWS\System32\drivers\acpiex.sys [136712] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - ACPI Processor Aggregator Device Driver.) -- C:\WINDOWS\System32\drivers\acpipagr.sys [12800] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:38 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\WINDOWS\System32\drivers\acpipmi.sys [16896] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - ACPI Wake Alarm.) -- C:\WINDOWS\System32\drivers\acpitime.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:56 A . (.Microsoft Corporation - Audio KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\Acx01000.sys [337920] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135632] =>.Microsoft Windows®
O58 - SDL:2020/07/01 20:30:49 A . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\afd.sys [661816] =>.Microsoft®
O58 - SDL:2020/05/08 07:14:47 A . (.Microsoft Corporation - AF_UNIX socket provider.) -- C:\WINDOWS\System32\drivers\afunix.sys [40960] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:52 A . (.Microsoft Corporation - Gerenciador de Chamadas de Miniporta VPN RA.) -- C:\WINDOWS\System32\drivers\agilevpn.sys [114176] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:41 A . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\WINDOWS\System32\drivers\ahcache.sys [291840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:33 A . (.Advanced Micro Devices, Inc - AMD GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\amdgpio2.sys [18432] [Unsigned] =>.Advanced Micro Devices, Inc
O58 - SDL:2019/03/19 01:43:33 A . (.Advanced Micro Devices, Inc - AMD I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\amdi2c.sys [37888] [Unsigned] =>.Advanced Micro Devices, Inc
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\amdk8.sys [199992] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\amdppm.sys [201528] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:39 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83464] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259600] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27176] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:17:56 A . (.Microsoft Corporation - AppID Driver.) -- C:\WINDOWS\System32\drivers\appid.sys [202552] =>.Microsoft®
O58 - SDL:2019/11/28 21:17:56 A . (.Microsoft Corporation - Applocker Filter.) -- C:\WINDOWS\System32\drivers\applockerfltr.sys [18432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:17:45 A . (.Microsoft Corporation - Microsoft Application Virtualization Stream.) -- C:\WINDOWS\System32\drivers\AppVStrm.sys [138040] =>.Microsoft®
O58 - SDL:2020/05/08 07:17:45 A . (.Microsoft Corporation - Microsoft Application Virtualization VE Man.) -- C:\WINDOWS\System32\drivers\AppvVemgr.sys [174392] =>.Microsoft®
O58 - SDL:2020/05/08 07:17:45 A . (.Microsoft Corporation - Microsoft Application Virtualization VFS Fi.) -- C:\WINDOWS\System32\drivers\AppvVfs.sys [153912] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:39 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [132112] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\WINDOWS\System32\drivers\asyncmac.sys [31232] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [30008] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\WINDOWS\System32\drivers\ataport.sys [222520] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:33 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athw8x.sys [4233728] [Unsigned] =>.Qualcomm Atheros Communications, Inc.
O58 - SDL:2013/04/17 13:59:56 A . (.BitDefender - Active Virus Control filter driver.) -- C:\WINDOWS\System32\drivers\avc3.sys [718840] =>.Bitdefender SRL®
O58 - SDL:2021/01/12 13:20:28 A . (.BitDefender - BitDefender AntiVirus Active Virus Control.) -- C:\WINDOWS\System32\drivers\avchv.sys [261056] =>.Bitdefender SRL®
O58 - SDL:2013/04/17 13:59:58 A . (.BitDefender - Active Virus Control Kernel Filtering drive.) -- C:\WINDOWS\System32\drivers\avckf.sys [593144] =>.Bitdefender SRL®
O58 - SDL:2019/03/19 01:44:01 A . (.Microsoft Corporation - BAM Kernel Driver.) -- C:\WINDOWS\System32\drivers\bam.sys [70456] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\WINDOWS\System32\drivers\battc.sys [41784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:34 A . (. - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] [Unsigned] =>.Broadcom Corporation
O58 - SDL:2019/03/19 01:44:32 A . (.Microsoft Corporation - BEEP Driver.) -- C:\WINDOWS\System32\drivers\beep.sys [10240] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:12:51 A . (.Microsoft Corporation - Windows Bind Filter Driver.) -- C:\WINDOWS\System32\drivers\bindflt.sys [117264] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:53 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\WINDOWS\System32\drivers\bowser.sys [117248] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:38 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\WINDOWS\System32\drivers\bridge.sys [127488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:33 A . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) -- C:\WINDOWS\System32\drivers\BtaMPM.sys [36352] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2016/07/13 17:47:38 A . (.Qualcomm Atheros - Qualcomm Atheros BtFilter Driver.) -- C:\WINDOWS\System32\drivers\btfilter.sys [610336] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2020/05/08 07:11:11 A . (.Microsoft Corporation - Bluetooth A2DP Driver.) -- C:\WINDOWS\System32\drivers\BthA2dp.sys [231936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:17 A . (.Microsoft Corporation - Extensor de Barramento Bluetooth.) -- C:\WINDOWS\System32\drivers\bthenum.sys [114688] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:33 A . (.Microsoft Corporation - Bluetooth Hands-free Audio Device Driver.) -- C:\WINDOWS\System32\drivers\BthHfAud.sys [57856] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:33 A . (.Microsoft Corporation - Bluetooth Hands-Free Audio and Call Control.) -- C:\WINDOWS\System32\drivers\BthHfEnum.sys [131072] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:17 A . (.Microsoft Corporation - Bluetooth Transport Extensibility Miniport.) -- C:\WINDOWS\System32\drivers\BthMini.SYS [36864] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\WINDOWS\System32\drivers\bthmodem.sys [76288] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Bluetooth Personal Area Networking.) -- C:\WINDOWS\System32\drivers\bthpan.sys [133120] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:17 A . (.Microsoft Corporation - Driver de Barramento Bluetooth.) -- C:\WINDOWS\System32\drivers\bthport.sys [1428992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:17 A . (.Microsoft Corporation - Driver de Miniporta Bluetooth.) -- C:\WINDOWS\System32\drivers\BTHUSB.SYS [99328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - VHD BTT Filter Driver.) -- C:\WINDOWS\System32\drivers\bttflt.sys [42808] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Button Converter Driver.) -- C:\WINDOWS\System32\drivers\buttonconverter.sys [43008] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:38 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [534032] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:34 A . (.Microsoft Corporation - Charge Arbiration Driver.) -- C:\WINDOWS\System32\drivers\CAD.sys [64312] =>.Microsoft Windows®
O58 - SDL:2019/12/12 15:23:25 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\cdfs.sys [100352] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\cdrom.sys [173056] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:01 A . (.Microsoft Corporation - Event Aggregation Kernel Mode Library.) -- C:\WINDOWS\System32\drivers\CEA.sys [82448] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:40 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [142864] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:40 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [319528] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Chelsio Communications - VF library for Chelsio ® T5/T6 Chipset.) -- C:\WINDOWS\System32\drivers\cht4vfx.sys [29696] [Unsigned] =>.Chelsio Communications
O58 - SDL:2019/03/19 01:43:41 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T5/T6 Chip.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [1866768] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\WINDOWS\System32\drivers\circlass.sys [51200] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:01 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\WINDOWS\System32\drivers\Classpnp.sys [416056] =>.Microsoft®
O58 - SDL:2020/07/01 20:29:18 A . (.Microsoft Corporation - Cloud Files Mini Filter Driver.) -- C:\WINDOWS\System32\drivers\cldflt.sys [457216] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 20:31:11 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\WINDOWS\System32\drivers\clfs.sys [400696] =>.Microsoft®
O58 - SDL:2019/11/28 21:17:15 A . (.Microsoft Corporation - CLIP Service.) -- C:\WINDOWS\System32\drivers\ClipSp.sys [1029432] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\WINDOWS\System32\drivers\CmBatt.sys [36864] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - Driver de Exportação do Host da Extensão de.) -- C:\WINDOWS\System32\drivers\cmimcext.sys [29200] =>.Microsoft Windows®
O58 - SDL:2020/07/01 20:30:11 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\WINDOWS\System32\drivers\cng.sys [752584] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - CNG Hardware Assist algorithm provider.) -- C:\WINDOWS\System32\drivers\cnghwassist.sys [40760] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:16 A . (.Microsoft Corporation - Console Driver.) -- C:\WINDOWS\System32\drivers\condrv.sys [58896] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:14:12 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\crashdmp.sys [98104] =>.Microsoft®
O58 - SDL:2020/05/08 07:17:58 A . (.Microsoft Corporation - Windows Client Side Caching Driver.) -- C:\WINDOWS\System32\drivers\csc.sys [576512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:00 A . (.Microsoft Corporation - DAM Kernel Driver.) -- C:\WINDOWS\System32\drivers\dam.sys [100152] =>.Microsoft Windows®
O58 - SDL:2019/12/04 22:23:34 A . (.Dropbox, Inc. - Dropbox Filter Driver.) -- C:\WINDOWS\System32\drivers\dbx-canary.sys [47600] =>.Microsoft®
O58 - SDL:2019/12/04 22:23:34 A . (.Dropbox, Inc. - Dropbox Filter Driver.) -- C:\WINDOWS\System32\drivers\dbx-dev.sys [47600] =>.Microsoft®
O58 - SDL:2019/12/04 22:23:34 A . (.Dropbox, Inc. - Dropbox Filter Driver.) -- C:\WINDOWS\System32\drivers\dbx-stable.sys [47600] =>.Microsoft®
O58 - SDL:2019/11/28 21:16:40 A . (.Microsoft Corporation - Xbox Device Authentication Driver.) -- C:\WINDOWS\System32\drivers\devauthe.sys [47104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:38 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\dfsc.sys [151040] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\WINDOWS\System32\drivers\disk.sys [98104] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:45 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\WINDOWS\System32\drivers\Diskdump.sys [37928] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:45 A . (.Microsoft Corporation - Boot Over USB Dump Driver.) -- C:\WINDOWS\System32\drivers\Dmpusbstor.sys [15360] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Memória Dinâmica.) -- C:\WINDOWS\System32\drivers\dmvsc.sys [58168] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\WINDOWS\System32\drivers\drmk.sys [98304] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\WINDOWS\System32\drivers\drmkaud.sys [16344] =>.Microsoft Windows®
O58 - SDL:2016/10/17 12:33:29 A . (.Disc Soft Ltd - DAEMON Tools Lite Virtual SCSI Bus Driver.) -- C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264] =>.Disc Soft Ltd®
O58 - SDL:2016/10/17 12:33:34 A . (.Disc Soft Ltd - DAEMON Tools Lite Virtual USB Bus Driver.) -- C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672] =>.Disc Soft Ltd®
O58 - SDL:2019/03/19 01:44:28 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\WINDOWS\System32\drivers\Dumpata.sys [36904] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:21:00 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\WINDOWS\System32\drivers\dumpfve.sys [93104] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:18 A . (.Microsoft Corporation - SD Crashdump Port Driver.) -- C:\WINDOWS\System32\drivers\dumpsd.sys [193848] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - SD Host Controller Crashdump Port Driver.) -- C:\WINDOWS\System32\drivers\dumpsdport.sys [32256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:45 A . (.Microsoft Corporation - Storport Dump Driver.) -- C:\WINDOWS\System32\drivers\Dumpstorport.sys [34616] =>.Microsoft Windows®
O58 - SDL:2020/07/01 16:26:42 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\WINDOWS\System32\drivers\dxgkrnl.sys [3581240] =>.Microsoft®
O58 - SDL:2020/07/01 16:26:45 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\WINDOWS\System32\drivers\dxgmms1.sys [441152] =>.Microsoft®
O58 - SDL:2020/07/01 16:27:07 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\WINDOWS\System32\drivers\dxgmms2.sys [874296] =>.Microsoft®
O58 - SDL:2019/03/19 01:45:38 A . (.Microsoft Corporation - Enhanced Storage Class driver for IEEE 1667.) -- C:\WINDOWS\System32\drivers\EhStorClass.sys [85520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Microsoft driver for storage devices suppor.) -- C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys [114696] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Error Device Driver.) -- C:\WINDOWS\System32\drivers\errdev.sys [14336] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419176] =>.Microsoft Windows®
O58 - SDL:2019/12/12 15:22:08 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\WINDOWS\System32\drivers\exfat.sys [404480] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/12/12 15:22:08 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\WINDOWS\System32\drivers\fastfat.sys [422712] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\WINDOWS\System32\drivers\fdc.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - Windows sandboxing and encryption filter.) -- C:\WINDOWS\System32\drivers\filecrypt.sys [59392] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:28 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\WINDOWS\System32\drivers\fileinfo.sys [94520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:28 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\WINDOWS\System32\drivers\filetrace.sys [40960] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - Floppy Driver.) -- C:\WINDOWS\System32\drivers\flpydisk.sys [28160] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:13 A . (.Microsoft Corporation - Gerenciador de Filtro do Filesystem Microso.) -- C:\WINDOWS\System32\drivers\fltMgr.sys [437776] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\WINDOWS\System32\drivers\fsdepends.sys [67896] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:35 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\WINDOWS\System32\drivers\fs_rec.sys [34320] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:21:00 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\WINDOWS\System32\drivers\fvevol.sys [800568] =>.Microsoft®
O58 - SDL:2020/07/01 20:30:51 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\WINDOWS\System32\drivers\FWPKCLNT.SYS [477496] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:45 A . (.Microsoft Corporation - GPU Energy Kernel Driver.) -- C:\WINDOWS\System32\drivers\gpuenergydrv.sys [8704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2013/04/22 12:21:00 A . (.BitDefender LLC - BitDefender Gonzales FileSystem Driver.) -- C:\WINDOWS\System32\drivers\gzflt.sys [148696] =>.Bitdefender SRL®
O58 - SDL:2020/05/08 07:11:12 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\hdaudbus.sys [114688] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:40 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\HdAudio.sys [425472] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\WINDOWS\System32\drivers\hidbatt.sys [39736] =>.Microsoft Windows®
O58 - SDL:2020/07/01 16:22:11 A . (.Microsoft Corporation - Driver de Miniporta Bluetooth para Disposit.) -- C:\WINDOWS\System32\drivers\hidbth.sys [121344] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:44 A . (.Microsoft Corporation - Biblioteca de Classes Hid.) -- C:\WINDOWS\System32\drivers\hidclass.sys [211968] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - I2C HID Miniport Driver.) -- C:\WINDOWS\System32\drivers\hidi2c.sys [54784] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - HID Button over Interrupt Driver.) -- C:\WINDOWS\System32\drivers\hidinterrupt.sys [53560] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\WINDOWS\System32\drivers\hidir.sys [48640] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:44 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\WINDOWS\System32\drivers\hidparse.sys [46080] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:44 A . (.Microsoft Corporation - SPI HID Miniport Driver.) -- C:\WINDOWS\System32\drivers\hidspi.sys [64000] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:44 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\WINDOWS\System32\drivers\hidusb.sys [45568] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64528] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:13:56 A . (.Microsoft Corporation - Pilha do protocolo HTTP.) -- C:\WINDOWS\System32\drivers\http.sys [1300280] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Hyper-V Crashdump.) -- C:\WINDOWS\System32\drivers\hvcrash.sys [32568] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:16:23 A . (.Microsoft Corporation - Hypervisor Boot Driver.) -- C:\WINDOWS\System32\drivers\hvservice.sys [84280] =>.Microsoft®
O58 - SDL:2019/03/19 01:45:54 A . (.Microsoft Corporation - Microsoft Hyper-V Socket Provider.) -- C:\WINDOWS\System32\drivers\hvsocket.sys [145208] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:14:01 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\WINDOWS\System32\drivers\hwpolicy.sys [33080] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Microsoft VMBus Synthetic Keyboard Driver.) -- C:\WINDOWS\System32\drivers\hyperkbd.sys [25400] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Microsoft VMBus Video Device Miniport Drive.) -- C:\WINDOWS\System32\drivers\HyperVideo.sys [42000] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de porta i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [119296] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [36352] [Unsigned] =>.Intel(R) Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [91136] [Unsigned] =>.Intel(R) Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [79360] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [93184] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [112128] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [96256] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [171520] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [175104] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [180736] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [177664] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:38 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2019/03/19 01:43:37 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAVC.sys [885048] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [411960] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [566800] =>.Microsoft Windows®
O58 - SDL:2017/09/25 01:00:12 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [7971792] =>.Intel(R) pGFX®
O58 - SDL:2019/03/19 01:44:16 A . (.Microsoft Corporation - Indirect displays kernel-mode filter driver.) -- C:\WINDOWS\System32\drivers\IndirectKmd.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2016/05/12 04:32:26 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [481768] =>.Intel(R) OWR®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\WINDOWS\System32\drivers\intelide.sys [19984] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:14 A . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\WINDOWS\System32\drivers\intelpep.sys [355000] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:34 A . (.Microsoft Corporation - Intel Power Limit Driver.) -- C:\WINDOWS\System32\drivers\intelpmax.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\intelppm.sys [224056] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:45 A . (.Microsoft Corporation - Filtro de controle de taxa de E/S.) -- C:\WINDOWS\System32\drivers\iorate.sys [56632] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\WINDOWS\System32\drivers\ipfltdrv.sys [90624] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - DRIVER WMI IPMI.) -- C:\WINDOWS\System32\drivers\IPMIDrv.sys [110904] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:16 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\ipnat.sys [224768] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - IPT Driver.) -- C:\WINDOWS\System32\drivers\ipt.sys [54584] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:16:43 A . (.Microsoft Corporation - PNP ISA Bus Driver.) -- C:\WINDOWS\System32\drivers\isapnp.sys [23352] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - Avago SAS Gen3.5 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\ItSas35i.sys [148520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de Classe de Teclado.) -- C:\WINDOWS\System32\drivers\kbdclass.sys [70968] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - HID Mouse Filter Driver.) -- C:\WINDOWS\System32\drivers\kbdhid.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Microsoft Kernel Debugger Network Miniport.) -- C:\WINDOWS\System32\drivers\kdnic.sys [32568] =>.Microsoft Windows®
O58 - SDL:2020/07/01 16:23:06 A . (.Microsoft Corporation - Network Power Dependency Broker.) -- C:\WINDOWS\System32\drivers\KNetPwrDepBroker.sys [30720] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:39 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\WINDOWS\System32\drivers\ks.sys [455680] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:14 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\WINDOWS\System32\drivers\ksecdd.sys [146744] =>.Microsoft Windows®
O58 - SDL:2020/07/01 20:30:12 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\WINDOWS\System32\drivers\ksecpkg.sys [179512] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:52 A . (.Microsoft Corporation - Kernel Streaming WOW Thunk Service.) -- C:\WINDOWS\System32\drivers\ksthunk.sys [29184] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:48 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\WINDOWS\System32\drivers\lltdio.sys [72192] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [109064] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [124448] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [128528] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82960] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:18:41 A . (.Microsoft Corporation - Driver do Filtro de Virtualização do Arquiv.) -- C:\WINDOWS\System32\drivers\luafv.sys [141312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - MA-USB Host Controller Driver.) -- C:\WINDOWS\System32\drivers\mausbhost.sys [535864] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - MA-USB IP Driver.) -- C:\WINDOWS\System32\drivers\mausbip.sys [62264] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:16:55 A . (.Microsoft Corporation - Windows Mobile Broadband Class Extension.) -- C:\WINDOWS\System32\drivers\MbbCx.sys [359424] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:33 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\WINDOWS\System32\drivers\mcd.sys [24576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59920] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [75280] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas35i.sys [94736] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [576016] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:33 A . (.Microsoft Corporation - Driver de Transporte Avrcp Bluetooth da Mic.) -- C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [64512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Legacy Bluetooth LE Bus Enumerator.) -- C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [97280] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [1150480] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:47 A . (.Microsoft Corporation - MMCSS Driver.) -- C:\WINDOWS\System32\drivers\mmcss.sys [53760] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:53 A . (.Microsoft Corporation - Driver de dispositivo de modem.) -- C:\WINDOWS\System32\drivers\modem.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:14 A . (.Microsoft Corporation - Monitor Driver.) -- C:\WINDOWS\System32\drivers\monitor.sys [69632] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de classe modem.) -- C:\WINDOWS\System32\drivers\mouclass.sys [66872] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - HID Mouse Filter Driver.) -- C:\WINDOWS\System32\drivers\mouhid.sys [35840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:13 A . (.Microsoft Corporation - Gerenciador de Pontos de Montagem.) -- C:\WINDOWS\System32\drivers\mountmgr.sys [113160] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:15 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\WINDOWS\System32\drivers\mpsdrv.sys [80384] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:20:10 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\WINDOWS\System32\drivers\mrxdav.sys [158208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 20:31:11 A . (.Microsoft Corporation - Minirdr SMB do Windows NT.) -- C:\WINDOWS\System32\drivers\mrxsmb.sys [561464] =>.Microsoft®
O58 - SDL:2020/05/08 07:14:14 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\WINDOWS\System32\drivers\mrxsmb20.sys [260920] =>.Microsoft®
O58 - SDL:2019/11/28 21:18:13 A . (.Microsoft Corporation - Mailslot driver.) -- C:\WINDOWS\System32\drivers\msfs.sys [43536] =>.Microsoft®
O58 - SDL:2019/11/28 21:17:18 A . (.Microsoft Corporation - GPIO Class Extension Driver.) -- C:\WINDOWS\System32\drivers\msgpioclx.sys [182288] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - GPIO Button Driver.) -- C:\WINDOWS\System32\drivers\msgpiowin32.sys [54072] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:16 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\WINDOWS\System32\drivers\mshidkmdf.sys [8704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - Driver pass-through para Interface HID-UMDF.) -- C:\WINDOWS\System32\drivers\mshidumdf.sys [12288] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:16 A . (.Microsoft Corporation - Hardware Notification Class Extension Drive.) -- C:\WINDOWS\System32\drivers\mshwnclx.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:43 A . (.Microsoft Corporation - ISA Driver.) -- C:\WINDOWS\System32\drivers\msisadrv.sys [19256] =>.Microsoft®
O58 - SDL:2019/11/28 21:16:43 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\WINDOWS\System32\drivers\msiscsi.sys [292664] =>.Microsoft®
O58 - SDL:2019/11/28 21:18:40 A . (.Microsoft Corporation - MS KS Server.) -- C:\WINDOWS\System32\drivers\mskssrv.sys [34816] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:00 A . (.Microsoft Corporation - Driver do Protocolo Microsoft LLDP.) -- C:\WINDOWS\System32\drivers\mslldp.sys [78848] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:52 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\WINDOWS\System32\drivers\mspclock.sys [11264] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:52 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\WINDOWS\System32\drivers\mspqm.sys [11264] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:14 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\WINDOWS\System32\drivers\msrpc.sys [372752] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:45 A . (.Microsoft Corporation - Driver do filtro do sistema de arquivos do.) -- C:\WINDOWS\System32\drivers\mssecflt.sys [254776] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\WINDOWS\System32\drivers\mssmbios.sys [48440] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:52 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\WINDOWS\System32\drivers\mstee.sys [12800] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - Driver HID Multitoque Microsoft.) -- C:\WINDOWS\System32\drivers\MTConfig.sys [16384] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:16 A . (.Microsoft Corporation - Driver de Provedor UNC Múltiplo.) -- C:\WINDOWS\System32\drivers\mup.sys [129848] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [64016] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [153616] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:14:04 A . (.Microsoft Corporation - NDIS (Especificação de Interface de Driver.) -- C:\WINDOWS\System32\drivers\ndis.sys [1482040] =>.Microsoft®
O58 - SDL:2019/03/19 01:45:50 A . (.Microsoft Corporation - Microsoft NDIS Packet Capture Filter Driver.) -- C:\WINDOWS\System32\drivers\ndiscap.sys [56320] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:46 A . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) -- C:\WINDOWS\System32\drivers\NdisImPlatform.sys [135168] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:56 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\WINDOWS\System32\drivers\ndistapi.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:35 A . (.Microsoft Corporation - Driver de E/S do modo de usuário NDIS.) -- C:\WINDOWS\System32\drivers\ndisuio.sys [70656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:00 A . (.Microsoft Corporation - Enumerador de Adaptador de Rede Virtual Mic.) -- C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [22016] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:53 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\WINDOWS\System32\drivers\ndiswan.sys [206336] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:50 A . (.Microsoft Corporation - RDMA Sample Driver.) -- C:\WINDOWS\System32\drivers\NDKPing.sys [63488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:56 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\WINDOWS\System32\drivers\ndproxy.sys [244736] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:32 A . (.Microsoft Corporation - Windows Network Data Usage Monitoring Drive.) -- C:\WINDOWS\System32\drivers\Ndu.sys [132096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:36 A . (.Microsoft Corporation - Network Adapter Class Extension for WDF.) -- C:\WINDOWS\System32\drivers\NetAdapterCx.sys [187904] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:58 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\WINDOWS\System32\drivers\netbios.sys [64824] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:18:54 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netbt.sys [337408] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:14 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\WINDOWS\System32\drivers\netio.sys [586768] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Miniporta NDIS Virtual.) -- C:\WINDOWS\System32\drivers\netvsc.sys [246072] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:18:13 A . (.Microsoft Corporation - NPFS Driver.) -- C:\WINDOWS\System32\drivers\npfs.sys [87048] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Named pipe service triggers.) -- C:\WINDOWS\System32\drivers\npsvctrig.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:14 A . (.Microsoft Corporation - NSI Proxy.) -- C:\WINDOWS\System32\drivers\nsiproxy.sys [48128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:02 A . (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2698040] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:53 A . (.Microsoft Corporation - NTOS extension host driver.) -- C:\WINDOWS\System32\drivers\ntosext.sys [20496] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:35 A . (.Microsoft Corporation - NULL Driver.) -- C:\WINDOWS\System32\drivers\null.sys [7680] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Driver de dispositivo NVDIMM.) -- C:\WINDOWS\System32\drivers\nvdimm.sys [158520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150544] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166408] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:17:03 A . (.Microsoft Corporation - Driver da Miniporta NativeWiFi.) -- C:\WINDOWS\System32\drivers\nwifi.sys [702464] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:15 A . (.Microsoft Corporation - Agendador de pacotes de serviço.) -- C:\WINDOWS\System32\drivers\pacer.sys [160784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Driver de porta paralela.) -- C:\WINDOWS\System32\drivers\parport.sys [108032] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:04 A . (.Microsoft Corporation - Partition driver.) -- C:\WINDOWS\System32\drivers\partmgr.sys [178192] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - Enumerador NT Plug and Play PCI.) -- C:\WINDOWS\System32\drivers\pci.sys [437560] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\WINDOWS\System32\drivers\pciide.sys [16912] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\WINDOWS\System32\drivers\pciidex.sys [56632] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:34 A . (.Microsoft Corporation - Driver de barramento PCMCIA.) -- C:\WINDOWS\System32\drivers\pcmcia.sys [127504] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:33 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\WINDOWS\System32\drivers\pcw.sys [58384] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:11:56 A . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\WINDOWS\System32\drivers\pdc.sys [180232] =>.Microsoft®
O58 - SDL:2019/11/28 21:16:59 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\WINDOWS\System32\drivers\PEAuth.sys [817152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58896] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [68624] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:45:50 A . (.Microsoft Corporation - Driver do Monitor de Pacotes.) -- C:\WINDOWS\System32\drivers\PktMon.sys [96056] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Driver de memória persistente.) -- C:\WINDOWS\System32\drivers\pmem.sys [127800] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:38 A . (.Microsoft Corporation - Plug and Play Memory Driver.) -- C:\WINDOWS\System32\drivers\pnpmem.sys [17408] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - Port Device Class Configuration Filter Driv.) -- C:\WINDOWS\System32\drivers\portcfg.sys [25600] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\WINDOWS\System32\drivers\portcls.sys [390656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\processr.sys [208696] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:15 A . (.Microsoft Corporation - Process Launch Monitor driver.) -- C:\WINDOWS\System32\drivers\ProcLaunchMon.sys [36248] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:45:00 A . (.Microsoft Corporation - Driver de Suporte do Microsoft Quality Wind.) -- C:\WINDOWS\System32\drivers\qwavedrv.sys [53760] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - RAM Disk Driver.) -- C:\WINDOWS\System32\drivers\ramdisk.sys [41784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\WINDOWS\System32\drivers\rasacd.sys [19968] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\rasl2tp.sys [112128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\raspppoe.sys [87552] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\WINDOWS\System32\drivers\raspptp.sys [103424] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\WINDOWS\System32\drivers\rassstp.sys [85504] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:14:13 A . (.Microsoft Corporation - Driver do Subsistema de Buffer da Unidade R.) -- C:\WINDOWS\System32\drivers\rdbss.sys [456504] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\WINDOWS\System32\drivers\rdpbus.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:20:01 A . (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Micros.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [167936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:17:02 A . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\WINDOWS\System32\drivers\rdpvideominiport.sys [32056] =>.Microsoft®
O58 - SDL:2019/03/19 01:45:56 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\WINDOWS\System32\drivers\rdyboost.sys [294928] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:13:16 A . (.Microsoft Corporation - Driver NT ReFS FS.) -- C:\WINDOWS\System32\drivers\refs.sys [1972536] =>.Microsoft®
O58 - SDL:2019/12/12 15:22:23 A . (.Microsoft Corporation - Driver NT ReFS FS.) -- C:\WINDOWS\System32\drivers\refsv1.sys [986936] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Bluetooth RFCOMM Driver.) -- C:\WINDOWS\System32\drivers\rfcomm.sys [211456] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Transporte de VM do Microsoft RemoteFX.) -- C:\WINDOWS\System32\drivers\RfxVmt.sys [41472] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:38 A . (.Microsoft Corporation - ResourceHub Proxy Driver.) -- C:\WINDOWS\System32\drivers\rhproxy.sys [113152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:43 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\WINDOWS\System32\drivers\rmcast.sys [159232] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\WINDOWS\System32\drivers\RNDISMP.sys [37376] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:53 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\WINDOWS\System32\drivers\rootmdm.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:48 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\WINDOWS\System32\drivers\rspndr.sys [89088] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Realtek - Realtek 8125/8136/8168/8169 NDIS 6.40 64-bi.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [662528] [Unsigned] =>.Realtek
O58 - SDL:2019/03/19 01:43:49 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\WINDOWS\System32\drivers\rteth.sys [57856] [Unsigned] =>.Realtek
O58 - SDL:2015/07/09 18:41:58 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [4522752] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/07/03 10:00:52 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\WINDOWS\System32\drivers\RtsUer.sys [410880] =>.Realtek Semiconductor Corp®
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\WINDOWS\System32\drivers\sbp2port.sys [117288] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:30 A . (.Microsoft Corporation - Driver de Filtro de Leitura de Cartão Intel.) -- C:\WINDOWS\System32\drivers\scfilter.sys [45056] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - Driver de Barramento de Memória de Classe d.) -- C:\WINDOWS\System32\drivers\scmbus.sys [151352] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:33 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\WINDOWS\System32\drivers\scsiport.sys [187408] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:11:18 A . (.Microsoft Corporation - SecureDigital Bus Driver.) -- C:\WINDOWS\System32\drivers\sdbus.sys [297272] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:38 A . (.Microsoft Corporation - SDF Reflector.) -- C:\WINDOWS\System32\drivers\SDFRd.sys [33592] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - SD Host Controller Port Driver.) -- C:\WINDOWS\System32\drivers\sdport.sys [105784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de Classe para Armazenamento SD.) -- C:\WINDOWS\System32\drivers\sdstor.sys [103736] =>.Microsoft Windows®
O58 - SDL:2015/06/04 13:33:50 A . (...) -- C:\WINDOWS\System32\drivers\semav6msr64.sys [21984] =>.Intel(R) Code Signing External®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - Serial Class Extension.) -- C:\WINDOWS\System32\drivers\SerCx.sys [84792] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\WINDOWS\System32\drivers\SerCx2.sys [170808] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\WINDOWS\System32\drivers\serenum.sys [27648] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Driver de dispositivo serial.) -- C:\WINDOWS\System32\drivers\serial.sys [89600] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de porta de mouse serial.) -- C:\WINDOWS\System32\drivers\sermouse.sys [29696] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:13 A . (.Microsoft Corporation - Serial Imaging Device Driver.) -- C:\WINDOWS\System32\drivers\serscan.sys [13312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\WINDOWS\System32\drivers\sfloppy.sys [18944] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:45:32 A . (.Microsoft Corporation - System Guard Runtime Monitor Agent Driver.) -- C:\WINDOWS\System32\drivers\SgrmAgent.sys [89096] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [45072] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81936] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:36 A . (.Microsoft Corporation - Sleep Study Helper.) -- C:\WINDOWS\System32\drivers\SleepStudyHelper.sys [38200] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:39 A . (.Microsemi Corportation - Storport Miniport Driver for SmartRAID/Smar.) -- C:\WINDOWS\System32\drivers\SmartSAMD.sys [220176] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:30 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\WINDOWS\System32\drivers\smclib.sys [21504] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:43 A . (.Microsoft Corporation - Storage Spaces Dump Driver.) -- C:\WINDOWS\System32\drivers\spacedump.sys [204816] =>.Microsoft®
O58 - SDL:2019/11/28 21:16:43 A . (.Microsoft Corporation - Storage Spaces Driver.) -- C:\WINDOWS\System32\drivers\spaceport.sys [657424] =>.Microsoft®
O58 - SDL:2019/03/19 09:49:25 A . (.Microsoft Corporation - Holographic Spatial Graph Filter.) -- C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [76088] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - SPB Class Extension.) -- C:\WINDOWS\System32\drivers\SpbCx.sys [85816] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:14:14 A . (.Microsoft Corporation - Driver de Servidor Smb 2.0.) -- C:\WINDOWS\System32\drivers\srv2.sys [772096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 20:31:12 A . (.Microsoft Corporation - Server Network driver.) -- C:\WINDOWS\System32\drivers\srvnet.sys [309248] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2016/09/05 05:47:06 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [131712] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2016/09/05 05:47:12 A . (.Samsung Electronics Co., Ltd. - SAMSUNG Android Modem Device Driver.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [165504] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2019/03/19 01:43:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31240] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - MS AHCI Storport Miniport Driver.) -- C:\WINDOWS\System32\drivers\storahci.sys [174392] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:16 A . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\WINDOWS\System32\drivers\stornvme.sys [141840] =>.Microsoft®
O58 - SDL:2020/07/01 16:23:45 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\WINDOWS\System32\drivers\storport.sys [637480] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - Filtro QoS de Armazenamento.) -- C:\WINDOWS\System32\drivers\storqosflt.sys [93200] =>.Microsoft Windows®
O58 - SDL:2020/07/01 16:22:10 A . (.Microsoft Corporation - MS UFS Storport Miniport Driver.) -- C:\WINDOWS\System32\drivers\storufs.sys [59192] =>.Microsoft®
O58 - SDL:2019/11/28 21:16:47 A . (.Microsoft Corporation - Storage VSC Driver.) -- C:\WINDOWS\System32\drivers\storvsc.sys [43536] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:33 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\WINDOWS\System32\drivers\stream.sys [82432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2015/08/05 03:41:42 A . (.Synaptics Incorporated - Synaptics I2C Driver.) -- C:\WINDOWS\System32\drivers\SynRMIHID.sys [56520] =>.Synaptics Incorporated®
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Microsoft RemoteFX Synth3D Video VSC.) -- C:\WINDOWS\System32\drivers\Synth3dVsc.sys [66560] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:33 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\WINDOWS\System32\drivers\tape.sys [33280] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:12:01 A . (.Microsoft Corporation - Export driver for kernel mode TPM API.) -- C:\WINDOWS\System32\drivers\tbs.sys [29712] =>.Microsoft®
O58 - SDL:2020/07/01 20:30:51 A . (.Microsoft Corporation - Driver TCP/IP.) -- C:\WINDOWS\System32\drivers\tcpip.sys [2986808] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:58 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\WINDOWS\System32\drivers\tcpipreg.sys [54784] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:36 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\WINDOWS\System32\drivers\tdi.sys [39440] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:45:32 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [132616] =>.Microsoft Windows®
O58 - SDL:2015/06/23 12:56:52 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [192312] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Terminal Server Input Driver.) -- C:\WINDOWS\System32\drivers\terminpt.sys [41488] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:18:16 A . (.Microsoft Corporation - Kernel Transaction Manager Driver.) -- C:\WINDOWS\System32\drivers\tm.sys [141840] =>.Microsoft®
O58 - SDL:2020/07/01 16:22:16 A . (.Microsoft Corporation - Driver de Dispositivo TPM.) -- C:\WINDOWS\System32\drivers\tpm.sys [250696] =>.Microsoft®
O58 - SDL:2013/05/28 11:12:19 A . (.BitDefender S.R.L. - Trufos Kernel Module.) -- C:\WINDOWS\System32\drivers\trufos.sys [382536] =>.Bitdefender SRL®
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - Driver do Filtro de Hub USB da Área de Trab.) -- C:\WINDOWS\System32\drivers\TsUsbFlt.sys [65024] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 16:22:08 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\WINDOWS\System32\drivers\TsUsbGD.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:23 A . (.Microsoft Corporation - Hub USB de Área de Trabalho Remota.) -- C:\WINDOWS\System32\drivers\tsusbhub.sys [132096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:53 A . (.Microsoft Corporation - Driver de Interface de Túnel Microsoft.) -- C:\WINDOWS\System32\drivers\tunnel.sys [128512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:44 A . (.Microsoft Corporation - Microsoft Uasp Driver.) -- C:\WINDOWS\System32\drivers\uaspstor.sys [79376] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - USB Connector Manager KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\UcmCx.sys [160256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - UCM-TCPCI KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [186368] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - UCM-UCSI ACPI Client Driver.) -- C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys [34816] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - UCM-UCSI KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\UcmUcsiCx.sys [111104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - USB Controller Extension.) -- C:\WINDOWS\System32\drivers\Ucx01000.sys [244024] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:49 A . (.Microsoft Corporation - "udecx.DRIVER".) -- C:\WINDOWS\System32\drivers\Udecx.sys [51200] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/12/12 15:23:31 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\WINDOWS\System32\drivers\udfs.sys [342528] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 09:49:26 A . (.Microsoft Corporation - Microsoft User Experience Virtualization Ag.) -- C:\WINDOWS\System32\drivers\UevAgentDriver.sys [41272] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - USB Function Driver Class Extension.) -- C:\WINDOWS\System32\drivers\ufx01000.sys [311096] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - UFX Synopsys Client Driver.) -- C:\WINDOWS\System32\drivers\ufxsynopsys.sys [181048] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\WINDOWS\System32\drivers\umpass.sys [13312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - USB Role-Switch Class Extension.) -- C:\WINDOWS\System32\drivers\urscx01000.sys [74552] =>.Microsoft Windows®
O58 - SDL:2016/08/16 03:18:34 A . (.MBB - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\usb2ser.sys [159936] =>.NGO®
O58 - SDL:2019/03/19 01:45:02 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\WINDOWS\System32\drivers\usb8023.sys [24576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - USB Audio Class Driver.) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys [198656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:40 A . (.Microsoft Corporation - Microsoft USB Audio Class 2.0 Driver.) -- C:\WINDOWS\System32\drivers\usbaudio2.sys [257536] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:38 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\WINDOWS\System32\drivers\USBCAMD2.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:17 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\WINDOWS\System32\drivers\usbccgp.sys [183608] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\WINDOWS\System32\drivers\usbcir.sys [107008] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\WINDOWS\System32\drivers\usbd.sys [33592] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\WINDOWS\System32\drivers\usbehci.sys [100664] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de Hub Padrão para USB.) -- C:\WINDOWS\System32\drivers\usbhub.sys [545592] =>.Microsoft Windows®
O58 - SDL:2020/07/01 16:22:12 A . (.Microsoft Corporation - Driver de HUB USB3.) -- C:\WINDOWS\System32\drivers\USBHUB3.SYS [634680] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\WINDOWS\System32\drivers\usbohci.sys [30208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:17:38 A . (...) -- C:\WINDOWS\System32\drivers\UsbPmApi.sys [53248] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de Porta USB 1.1 e 2.0.) -- C:\WINDOWS\System32\drivers\usbport.sys [475144] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - USB Printer driver.) -- C:\WINDOWS\System32\drivers\usbprint.sys [34304] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - USB Serial Driver.) -- C:\WINDOWS\System32\drivers\usbser.sys [79360] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Driver de Classe de Armazenamento em Massa.) -- C:\WINDOWS\System32\drivers\USBSTOR.SYS [134968] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\WINDOWS\System32\drivers\usbuhci.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 16:22:06 A . (.Microsoft Corporation - USB Video Class Driver.) -- C:\WINDOWS\System32\drivers\usbvideo.sys [306496] =>.Microsoft®
O58 - SDL:2020/07/01 16:22:13 A . (.Microsoft Corporation - Driver USB XHCI.) -- C:\WINDOWS\System32\drivers\USBXHCI.SYS [531768] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\WINDOWS\System32\drivers\vdrvroot.sys [60216] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:35 A . (.Microsoft Corporation - Extensão do Verificador de Driver.) -- C:\WINDOWS\System32\drivers\VerifierExt.sys [321040] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:11:17 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\WINDOWS\System32\drivers\vhdmp.sys [804872] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Virtual HID Framework (VHF) Driver.) -- C:\WINDOWS\System32\drivers\vhf.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:46 A . (.Microsoft Corporation - Microsoft Hyper-V Virtualization Infrastruc.) -- C:\WINDOWS\System32\drivers\Vid.sys [551736] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:38 A . (.Microsoft Corporation - Video Port Driver.) -- C:\WINDOWS\System32\drivers\videoprt.sys [47104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:20:09 A . (.Microsoft Corporation - Hyper-V VMBus KMCL.) -- C:\WINDOWS\System32\drivers\vmbkmcl.sys [100664] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:22 A . (.Microsoft Corporation - Driver Filho do Barramento VMBus do Microso.) -- C:\WINDOWS\System32\drivers\vmbus.sys [151568] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\WINDOWS\System32\drivers\VMBusHID.sys [36152] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Virtual Machine Generation Counter.) -- C:\WINDOWS\System32\drivers\vmgencounter.sys [22328] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Virtual Machine Guest Infrastructure Driver.) -- C:\WINDOWS\System32\drivers\vmgid.sys [18232] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\WINDOWS\System32\drivers\vms3cap.sys [17208] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:16:47 A . (.Microsoft Corporation - Driver do Filtro de Armazenamento Virtual.) -- C:\WINDOWS\System32\drivers\vmstorfl.sys [52752] =>.Microsoft®
O58 - SDL:2020/05/08 07:11:15 A . (.Microsoft Corporation - Driver de Gerenciador de Volumes.) -- C:\WINDOWS\System32\drivers\volmgr.sys [89912] =>.Microsoft®
O58 - SDL:2019/03/19 01:45:38 A . (.Microsoft Corporation - Driver de Extensão do Gerenciador de Volume.) -- C:\WINDOWS\System32\drivers\volmgrx.sys [388112] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:12:08 A . (.Microsoft Corporation - Driver de Cópia de Sombra de Volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [429880] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - Volume driver.) -- C:\WINDOWS\System32\drivers\volume.sys [16696] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:44 A . (.Microsoft Corporation - Virtual PCI Bus.) -- C:\WINDOWS\System32\drivers\vpci.sys [83768] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:40 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166928] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:40 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305672] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:55 A . (.Microsoft Corporation - Virtual Wireless Bus Driver.) -- C:\WINDOWS\System32\drivers\vwifibus.sys [27648] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:55 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\WINDOWS\System32\drivers\vwififlt.sys [77312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:55 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\WINDOWS\System32\drivers\vwifimp.sys [50176] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:39 A . (.Microsoft Corporation - Driver HID do Tablet com Caneta Serial Waco.) -- C:\WINDOWS\System32\drivers\wacompen.sys [31744] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:56 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\WINDOWS\System32\drivers\wanarp.sys [92672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:06 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\WINDOWS\System32\drivers\watchdog.sys [66048] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:12:51 A . (.Microsoft Corporation - Windows Container Isolation FS Filter Drive.) -- C:\WINDOWS\System32\drivers\wcifs.sys [201744] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:16 A . (.Microsoft Corporation - Windows Container Name Virtualization FS Fi.) -- C:\WINDOWS\System32\drivers\wcnfs.sys [92672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:57 A . (.Microsoft Corporation - Microsoft antimalware boot driver.) -- C:\WINDOWS\System32\drivers\WdBoot.sys [46472] =>.Microsoft®
O58 - SDL:2020/07/01 20:30:48 A . (.Microsoft Corporation - Tempo de Execução da Estrutura de Driver em.) -- C:\WINDOWS\System32\drivers\Wdf01000.sys [847168] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:57 A . (.Microsoft Corporation - Microsoft antimalware file system filter dr.) -- C:\WINDOWS\System32\drivers\WdFilter.sys [333784] =>.Microsoft®
O58 - SDL:2020/07/01 20:30:48 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\WINDOWS\System32\drivers\WdfLdr.sys [58696] =>.Microsoft®
O58 - SDL:2019/11/28 21:17:03 A . (.Microsoft Corporation - WDI Driver Framework Driver.) -- C:\WINDOWS\System32\drivers\WdiWiFi.sys [931840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:21 A . (.Microsoft Corporation - WDM Companion Filter.) -- C:\WINDOWS\System32\drivers\WdmCompanionFilter.sys [21816] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:57 A . (.Microsoft Corporation - Windows Defender Network Stream Filter.) -- C:\WINDOWS\System32\drivers\WdNisDrv.sys [62432] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:35 A . (.Microsoft Corporation - Windows Error Reporting Kernel Driver.) -- C:\WINDOWS\System32\drivers\werkernel.sys [50488] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:17:35 A . (.Microsoft Corporation - WFP NDIS 6.30 Lightweight Filter Driver.) -- C:\WINDOWS\System32\drivers\wfplwfs.sys [180536] =>.Microsoft Windows®
O58 - SDL:2020/05/08 07:13:22 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\WINDOWS\System32\drivers\wimmount.sys [37392] =>.Microsoft®
O58 - SDL:2019/03/19 01:44:18 A . (.Microsoft Corporation - Windows Trusted Runtime Interface Driver.) -- C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [75752] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Windows Trusted Runtime Service Proxy Drive.) -- C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [17896] =>.Microsoft®
O58 - SDL:2019/03/19 01:45:54 A . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\WINDOWS\System32\drivers\winhv.sys [32568] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:19:40 A . (.Microsoft Corporation - Windows Hypervisor Root Interface Driver.) -- C:\WINDOWS\System32\drivers\winhvr.sys [84488] =>.Microsoft®
O58 - SDL:2019/03/19 01:43:41 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [37928] =>.Microsoft Windows®
O58 - SDL:2020/07/01 16:23:44 A . (.Microsoft Corporation - Driver NAT do Windows.) -- C:\WINDOWS\System32\drivers\winnat.sys [251392] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:18:09 A . (.Microsoft Corporation - Windows QUIC Driver.) -- C:\WINDOWS\System32\drivers\winquic.sys [205112] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:43 A . (.Microsoft Corporation - Windows WinUSB Class Driver.) -- C:\WINDOWS\System32\drivers\winusb.sys [105472] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:41 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [77832] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:43:41 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\WINDOWS\System32\drivers\wmiacpi.sys [19456] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:36 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\WINDOWS\System32\drivers\wmilib.sys [20496] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:17:58 A . (.Microsoft Corporation - Filtro de sobreposição do Windows.) -- C:\WINDOWS\System32\drivers\wof.sys [225080] =>.Microsoft®
O58 - SDL:2019/03/19 09:49:27 A . (.Microsoft Corporation - Windows Portable Device Upper Class Filter.) -- C:\WINDOWS\System32\drivers\WpdUpFltr.sys [31248] =>.Microsoft Windows®
O58 - SDL:2019/03/19 01:44:36 A . (.Microsoft Corporation - WPP Trace Recorder.) -- C:\WINDOWS\System32\drivers\WppRecorder.sys [39976] =>.Microsoft Windows®
O58 - SDL:2019/11/28 21:18:18 A . (.Microsoft Corporation - Winsock2 IFS Layer.) -- C:\WINDOWS\System32\drivers\ws2ifsl.sys [25088] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:37 A . (.Microsoft Corporation - Web Services Print Device Driver.) -- C:\WINDOWS\System32\drivers\WSDPrint.sys [24576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/08 07:11:13 A . (.Microsoft Corporation - Web Service Based Scan Device Driver.) -- C:\WINDOWS\System32\drivers\WSDScan.sys [26112] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:53 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\WINDOWS\System32\drivers\WUDFPf.sys [134656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:53 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\WINDOWS\System32\drivers\WUDFRd.sys [297984] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/28 21:16:40 A . (.Microsoft Corporation - Game Input Protocol Driver.) -- C:\WINDOWS\System32\drivers\xboxgip.sys [324608] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:43:33 A . (.Microsoft Corporation - XINPUT filter driver for HID.) -- C:\WINDOWS\System32\drivers\xinputhid.sys [48128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 16:28:42 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\WINDOWS\System32\win32k.sys [550400] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 16:27:07 A . (.Microsoft Corporation - Driver de Kernel de Win32k Base.) -- C:\WINDOWS\System32\win32kbase.sys [2716672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 16:28:42 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\WINDOWS\System32\win32kfull.sys [3726848] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 01:44:15 A . (.Microsoft Corporation - Win32k non session driver.) -- C:\WINDOWS\System32\win32kns.sys [30208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 20:34:05 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\WINDOWS\SysWOW64\win32k.sys [324096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/01 20:34:10 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\WINDOWS\SysWOW64\win32kfull.sys [2798592] [Unsigned] =>.Microsoft Corporation

---\\ Associações Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos.) -- C:\Windows\System32\eventvwr.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- "C:\WINDOWS\System32\WScript.exe" "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\Windows\regedit.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value

---\\ Menu de inicialização Internet (16) - 1s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Show IE Icon Utility.) -- C:\WINDOWS\System32\ie4ushowIE.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Show IE Icon Utility.) -- C:\WINDOWS\System32\ie4ushowIE.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation

---\\ Pesquisa de infeção nos navegadores da Internet (1) - 0s
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Listagem dos serviços iniciados pelo Svchost (50) - 5s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\WINDOWS\System32\certprop.dll [192512] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Car.) -- C:\Windows\System32\certprop.dll [192512] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\Windows\System32\srvsvc.dll [280064] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [1261568] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\IKEEXT.DLL [1042944] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\Windows\System32\iphlpsvc.dll [832000] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\Windows\System32\seclogon.dll [31232] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\Windows\System32\iscsiexe.dll [151040] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\Windows\System32\eapsvc.dll [110080] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\Windows\System32\schedsvc.dll [858112] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [231424] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [489984] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho.) -- C:\Windows\System32\SessEnv.dll [483328] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\Windows\System32\wercplsupport.dll [125440] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [269824] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [2465792] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: TroubleshootingSvc (TroubleshootingSvc) . (.Microsoft Corporation - MitigationClient.) -- C:\Windows\System32\MitigationClient.dll [394752] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: LxpSvc (LxpSvc) . (.Microsoft Corporation - Fornece suporte de infraestrutura para impl.) -- C:\Windows\System32\LanguageOverlayServer.dll [317952] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [239104] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1263616] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL do Serviço de Gerenciamento do Windows.) -- C:\Windows\System32\Windows.Internal.Management.dll [929280] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\Windows\System32\themeservice.dll [67072] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: WManSvc (WManSvc) . (.Microsoft Corporation - DLL do serviço de gerenciamento do Windows.) -- C:\Windows\System32\Windows.Management.Service.dll [921600] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Agente de Token.) -- C:\Windows\System32\TokenBroker.dll [1498624] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Serviço de Geolocalização.) -- C:\Windows\System32\lfsvc.dll [47104] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acess.) -- C:\Windows\System32\rasauto.dll [104448] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\Windows\System32\rasmans.dll [912896] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [500224] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistem.) -- C:\Windows\System32\Sens.dll [73728] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\Windows\System32\ipnathlp.dll [629760] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft® Windows.) -- C:\Windows\System32\tapisrv.dll [309248] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [3109376] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tel.) -- C:\Windows\System32\qmgr.dll [1583104] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [252928] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [58368] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Configurações da Nova Versão.) -- C:\Windows\System32\flightsettings.dll [893952] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Serviço de Configuração de Rede.) -- C:\Windows\System32\NetSetupSvc.dll [336896] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Serviço do Sistema de Notificação por Push.) -- C:\Windows\System32\WpnService.dll [263168] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1268224] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Atualizar Session Orchestrator Service.) -- C:\Windows\System32\usosvc.dll [544256] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [1283072] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\Windows\System32\DeviceSetupManager.dll [265728] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [2157056] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [72704] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede.) -- C:\Windows\System32\NcaSvc.dll [170496] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\Windows\System32\appinfo.dll [182272] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [1063936] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Serviço de Autenticação Natural.) -- C:\Windows\System32\NaturalAuth.dll [831488] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação do software.) -- C:\Windows\System32\appmgmts.dll [198656] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [526336] [Unsigned] =>.Microsoft Corporation

---\\ Lista das exceções do FireWall (FirewallRules) (28) - 6s
O87 - FAEL: "UDP Query User{3119B2D1-A849-4812-A28B-9E7FD20447C8}C:\program files (x86)\age of empires ii definitive edition\battleserver\battleserver.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\age of empires ii definitive edition\battleserver\battleserver.exe [Unsigned]
O87 - FAEL: "TCP Query User{5ABE19EF-B568-4CA1-9667-D6CCE0460B1F}C:\program files (x86)\age of empires ii definitive edition\battleserver\battleserver.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\age of empires ii definitive edition\battleserver\battleserver.exe [Unsigned]
O87 - FAEL: "{B582BB8D-431C-4E22-9C0B-22C6AA500ED2}" [In-None-P17-TRUE] .(.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe =>.Piriform Software Ltd®
O87 - FAEL: "{B5B581FA-893C-4413-9CF4-515E32863CDB}" [In-None-P6-TRUE] .(.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe =>.Piriform Software Ltd®
O87 - FAEL: "{A6A204FA-246D-4B93-81DF-3B75E14902B0}" [In-None-P6-TRUE] .(.Disc Soft Ltd - Disc Soft Bus Service Lite.) -- C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe =>.AVB Disc Soft, SIA®
O87 - FAEL: "{36A7B143-EDBD-4A9C-BE9F-A885A81E2068}" [In-None-P17-TRUE] .(.Hewlett-Packard Company - HP Installer.) -- C:\Program Files (x86)\HP\csiInstaller\8c0c6b8e-5f52-48bc-afe5-e43403a7d16e\Installer\hpbcsiInstaller.exe =>.Hewlett-Packard Company®
O87 - FAEL: "{8F74E67D-3B3F-4253-8EEE-F36F16760301}" [In-None-P6-TRUE] .(.Hewlett-Packard Company - HP Installer.) -- C:\Program Files (x86)\HP\csiInstaller\8c0c6b8e-5f52-48bc-afe5-e43403a7d16e\Installer\hpbcsiInstaller.exe =>.Hewlett-Packard Company®
O87 - FAEL: "{5986D056-4ABD-4501-9EE2-58AB4B4308B5}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - FaxPrinterUtility.) -- C:\Program Files\HP\HP LaserJet Pro MFP M521\bin\FaxPrinterUtility.exe =>.Hewlett Packard®
O87 - FAEL: "{2FB461D7-EF62-4ADA-B6BA-A2E96049479B}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - HPNetworkCommunicator.) -- C:\Program Files\HP\HP LaserJet Pro MFP M521\Bin\HPNetworkCommunicator.exe =>.Hewlett Packard®
O87 - FAEL: "{AB487A3B-871E-4E75-AB1D-7955D3993A0F}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - EWSProxy.) -- C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\bin\EWSProxy.exe =>.Hewlett Packard®
O87 - FAEL: "{1BDCCE0B-B047-486E-AE7B-2B75E36C55F8}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - HPNetworkCommunicator.) -- C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\Bin\HPNetworkCommunicator.exe =>.Hewlett Packard®
O87 - FAEL: "{D3C5B567-0909-4189-91D6-E519B1EB5591}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - DigitalWizards.) -- C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\bin\DigitalWizards.exe =>.Hewlett Packard®
O87 - FAEL: "{CB2135AA-1B5C-4A76-AB24-D43D79C2AED6}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - FaxApplications.) -- C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\bin\FaxApplications.exe =>.Hewlett Packard®
O87 - FAEL: "{EF860783-B86D-436D-A7C6-4946B2762A55}" [In-None-P6-TRUE] .(.Hewlett-Packard Co. - SendAFax.) -- C:\Program Files\HP\HP LaserJet Pro MFP M521\bin\SendAFax.exe =>.Hewlett Packard®
O87 - FAEL: "{5CAD82B3-907F-43BD-A677-2E2842674680}" [In-None-P17-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "{83C65055-836B-4E85-BA13-0E15E14B1094}" [In-None-P6-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "TCP Query User{95E12145-AAC0-415D-B460-C20D2A9E2D2F}C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe" [In-None-P6-TRUE] .(.2011 CD Projekt Red - Changelist: 1.) -- C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe [Unsigned]
O87 - FAEL: "UDP Query User{B82CE78E-37AE-4C3E-9D4C-F8655E2FC604}C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe" [In-None-P17-TRUE] .(.2011 CD Projekt Red - Changelist: 1.) -- C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe [Unsigned]
O87 - FAEL: "TCP Query User{31D9D9FC-473A-4A67-A87D-6F001FCE12CF}C:\program files (x86)\resident evil 6\bh6.exe" [In-None-P6-TRUE] .(.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) -- C:\program files (x86)\resident evil 6\bh6.exe =>.QLOC S.A.®
O87 - FAEL: "UDP Query User{21130FCF-1093-4EC8-A05B-85FDB93A69F4}C:\program files (x86)\resident evil 6\bh6.exe" [In-None-P17-TRUE] .(.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) -- C:\program files (x86)\resident evil 6\bh6.exe =>.QLOC S.A.®
O87 - FAEL: "TCP Query User{444B97FE-1D41-4D29-BB34-88A1AFC551E4}C:\program files (x86)\resident evil 6\bh6.exe" [In-None-P6-TRUE] .(.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) -- C:\program files (x86)\resident evil 6\bh6.exe =>.QLOC S.A.®
O87 - FAEL: "UDP Query User{CEA6DB62-49F1-47E8-B2C8-927015DFDAA8}C:\program files (x86)\resident evil 6\bh6.exe" [In-None-P17-TRUE] .(.CAPCOM U.S.A, INC. - RESIDENT EVIL 6.) -- C:\program files (x86)\resident evil 6\bh6.exe =>.QLOC S.A.®
O87 - FAEL: "{ABA2964E-D3C7-4343-9919-4EE3038F0540}" [In-None-P17-TRUE] .(.Dropbox, Inc. - Dropbox.) -- C:\Program Files (x86)\Dropbox\Client\Dropbox.exe =>.Dropbox, Inc®
O87 - FAEL: "{3E0C8998-6A3C-4A72-A1F1-EB6F3CAA9144}" [In-None-P17-TRUE] .(.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O87 - FAEL: "{49175938-2D06-495D-A0F9-4499C2F04A94}" [In-None-P6-TRUE] .(...) -- C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O87 - FAEL: "{D2B29CEB-2BAE-4AB2-A90E-FC7EFBA0E4F6}" [In-None-P17-TRUE] .(...) -- C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O87 - FAEL: "{940B4C85-0BBE-47F1-9FAA-08CB2D3F3A56}" [In-None-P6-TRUE] .(...) -- C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]
O87 - FAEL: "{0F0CC6CE-B9F8-43E6-80E9-6399D75D3A02}" [In-None-P17-TRUE] .(...) -- C:\Program Files\qBittorrent\qbittorrent.exe [Unsigned]

---\\ Listagem dos códigos dos software (47) - 1s
O90 - PUC: "00006109090061400000000000F01FEC" [HKLM] . (.Microsoft DCF MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2016.) =>.Microsoft Corporation
O90 - PUC: "000061091A0061400000000000F01FEC" [HKLM] . (.Microsoft OneNote MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061091E0061400000000000F01FEC" [HKLM] . (.Microsoft Office OSM MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061092E0061400000000000F01FEC" [HKLM] . (.Microsoft Office OSM UX MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109440061400000000000F01FEC" [HKLM] . (.Microsoft InfoPath MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109510061400000000000F01FEC" [HKLM] . (.Microsoft Access MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109610061400000000000F01FEC" [HKLM] . (.Microsoft Excel MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109810061400000000000F01FEC" [HKLM] . (.Microsoft PowerPoint MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109910061400000000000F01FEC" [HKLM] . (.Microsoft Publisher MUI (Portuguese (Brazil)) 2016.) =>.bl.org
O90 - PUC: "00006109A10061400000000000F01FEC" [HKLM] . (.Microsoft Outlook MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109A20000000100000000F01FEC" [HKLM] . (.Microsoft Office 64-bit Components 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109A20061400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 64-bit MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109AB0061400000000000F01FEC" [HKLM] . (.Microsoft Groove MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109B10061400000000000F01FEC" [HKLM] . (.Microsoft Word MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109B21061400000000000F01FEC" [HKLM] . (.Microsoft Skype for Business MUI (Portuguese (Brazil)) 2016.) =>.Skype Technologies
O90 - PUC: "00006109C20061400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109E60061400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (Portuguese (Brazil)) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109F10061400000000000F01FEC" [HKLM] . (.Revisores de Texto do Microsoft Office 2016 – Português (Brasil).) -- C:\Windows\Installer\{90160000-001F-0416-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2016 - English.) -- C:\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F100A0C00000000000F01FEC" [HKLM] . (.Herramientas de corrección de Microsoft Office 2016: español.) -- C:\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "071C8ED5817BDCB439593B3BBEEEAF12" [HKLM] . (.hppM521LaserJetService.) =>.Hewlett-Packard
O90 - PUC: "2780931F005280444AC6DC619C066C16" [HKLM] . (.HP Unified IO.) =>.Hewlett-Packard
O90 - PUC: "299F8313B54055F428C5352B136E74AC" [HKLM] . (.64 Bit HP CIO Components Installer.) =>.Hewlett-Packard
O90 - PUC: "30B85E29B27DE4D43A98758335381684" [HKLM] . (.HP LaserJet Pro MFP M521 HP Device Toolbox.) =>.Hewlett-Packard
O90 - PUC: "3128052F989958E40A8727EB849371FE" [HKLM] . (.Microsoft Games for Windows - LIVE Redistributable.) -- c:\Windows\Installer\{F2508213-9989-4E85-A078-72BE483917EF}\GameForWindowsLiveRedist.exe =>.bl.org
O90 - PUC: "38E9610BB75766FE2E0F9391447D58CB" [HKLM] . (.Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64).) =>.Microsoft Corporation
O90 - PUC: "5143CC8BF9212BD45A4CA49F116ACE86" [HKLM] . (.hpbM521DSService.) =>.Hewlett-Packard
O90 - PUC: "5A812990327ACD34D85B163756A6E149" [HKLM] . (.Dropbox Update Helper.) =>.WINSE
O90 - PUC: "6895F742EAA418343AEDC9E91DA16D85" [HKLM] . (.HP LaserJet Pro MFP M521 Fax Driver.) =>.Hewlett-Packard
O90 - PUC: "68AB67CA408033019195008142049602" [HKLM] . (.Adobe Refresh Manager.) -- C:\WINDOWS\Installer\{AC76BA86-0804-1033-1959-001824406920}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "68AB67CA7DA76401B744CAF070E41400" [HKLM] . (.Adobe Acrobat Reader DC - Português.) -- C:\Windows\Installer\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}\SC_Reader.ico =>.Adobe Inc.
O90 - PUC: "87E099EACB089974299CF283DCE9D21C" [HKLM] . (.HP LaserJet Pro MFP M521 Fax.) =>.Hewlett-Packard
O90 - PUC: "99D944AFCF21DE14493B8530C2C85372" [HKLM] . (.hpStatusAlerts.) =>.Hewlett-Packard
O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "ADA3E1E0966762F605507B4B58975F13" [HKLM] . (.AxCrypt 2.1.1481.0.) -- C:\WINDOWS\Installer\{0E1E3ADA-7669-6F26-5005-B7B48579F531}\axcrypt.ico =>.Axantum
O90 - PUC: "BCD2202629AB2CE4EA30B949E6D4FB21" [HKLM] . (.hpbDSService.) =>.Hewlett-Packard
O90 - PUC: "C7030BC4E565144468EBD02F4EBF28C8" [HKLM] . (.Microsoft Games for Windows Marketplace.) -- c:\Windows\Installer\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}\GameForWindowsLiveDash.exe =>.Microsoft Corporation
O90 - PUC: "C7DBA6E2EAE507D49AC0D5DCDA1F9238" [HKLM] . (.HP LJ M521 Scan HP Scan.) =>.Hewlett-Packard
O90 - PUC: "D04BB691875110D32B98EBCF771AA1E1" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319.) =>.bl.org
O90 - PUC: "D0DE67C5F6F05894B8439FEA874348F8" [HKLM] . (.HP Unified IO.) =>.Hewlett-Packard
O90 - PUC: "E128CD23D7A48784EB8E33F71A357D2F" [HKLM] . (.Update for Windows 10 for x64-based Systems (KB4023057).) =>.Microsoft Corporation
O90 - PUC: "E9061252E32E31F4881B8FAEC85D1EDF" [HKLM] . (.hppLaserJetService.) =>.Hewlett-Packard
O90 - PUC: "EBF8ACB0C1C056C4893AD543AA4F7173" [HKLM] . (.Microsoft Update Health Tools.) =>.Microsoft Corporation
O90 - PUC: "F021859125E512842AA57FAECCE14975" [HKLM] . (.hpStatusAlertsM521.) =>.Hewlett-Packard
O90 - PUC: "F173C5F32AE852F4D9D30D4B25E6A3AE" [HKLM] . (.NVIDIA PhysX.) =>.nVidia Corporation
O90 - PUC: "F7C3F5BF81E0D6543B4CB083AFD02E52" [HKLM] . (.HP LaserJet Pro MFP M521 Fax.) =>.Hewlett-Packard

---\\ Pesquisa dos pacotes WindowsInstaller (40) - 47s
[MD5.8561AE7FFAA5EEF2A6C00B91A050D8EB] [WIS][2012/09/10 04:49:12] (.HP - HP Unified IO.) -- C:\WINDOWS\Installer\191f7286.msi [937984] =>.HP
[MD5.0907B6D7F137D3C6F401A2F85398DB93] [WIS][2012/09/10 04:50:00] (.HP - HP Unified IO.) -- C:\WINDOWS\Installer\191f728a.msi [1916928] =>.HP
[MD5.C89E666070D7E137AE83892AD4DDD91E] [WIS][2014/08/14 03:48:16] (.
- .) -- C:\WINDOWS\Installer\191f728e.msi [735232]
[MD5.FB6AAEC8064604F05401532084FF752E] [WIS][2012/06/19 19:39:10] (.
- .) -- C:\WINDOWS\Installer\191f7292.msi [412672]
[MD5.0AC26F9617D5A2A44A35EF1178E3E702] [WIS][2012/07/31 20:28:00] (.Hewlett-Packard - 64 Bit HP CIO Components Installer Package.) -- C:\WINDOWS\Installer\191f7298.msi [500736] =>.Hewlett-Packard
[MD5.C3CCF644E498E0F42360B95BF9B8E9C8] [WIS][2012/11/18 12:45:04] (.Hewlett-Packard - hppM521LaserJetService.) -- C:\WINDOWS\Installer\191f729c.msi [32768] =>.Hewlett-Packard
[MD5.3B6979C7DFC0D8DD8C509FD81B3D2528] [WIS][2012/11/18 12:43:20] (.
- .) -- C:\WINDOWS\Installer\191f72a0.msi [1057792]
[MD5.61A41FD51F28688ED5F3D06DD65CF0A4] [WIS][2012/11/01 09:09:56] (.Hewlett-Packard Co. - HP LaserJet Pro MFP M521 Fax.) -- C:\WINDOWS\Installer\191f72a4.msi [458752] =>.Hewlett-Packard Co.
[MD5.63964CAA903C3A56AD3A39B61A272DE1] [WIS][2012/11/01 09:16:04] (.Hewlett-Packard Co. - HP LaserJet Pro MFP M521 Fax.) -- C:\WINDOWS\Installer\191f72a8.msi [10420224] =>.Hewlett-Packard Co.
[MD5.6CB4DF29899B9F6AA1380F589DACB807] [WIS][2012/08/10 18:55:02] (.Hewlett-Packard Co. - HP LJ M521 Scan HP Scan.) -- C:\WINDOWS\Installer\191f72ac.msi [56320] =>.Hewlett-Packard Co.
[MD5.04422D790AF026E78724E4E22D288E77] [WIS][2012/10/29 23:21:40] (.Hewlett-Packard - hpStatusAlertsM521.) -- C:\WINDOWS\Installer\191f72b1.msi [249856] =>.Hewlett-Packard
[MD5.85971755EA1C023C7C1E41A34BD7164F] [WIS][2012/11/29 23:06:20] (.Hewlett Packard - hpStatusAlerts.) -- C:\WINDOWS\Installer\191f72b5.msi [278528] =>.Hewlett Packard
[MD5.6EEB57ED8F333243511986C4E8E8F5DC] [WIS][2012/11/01 09:16:06] (.Hewlett-Packard Co. - HP LaserJet Pro MFP M521 HP Device Toolbox.) -- C:\WINDOWS\Installer\191f72b9.msi [3301376] =>.Hewlett-Packard Co.
[MD5.5415CB48251931507544A0736D6BEE48] [WIS][2012/11/01 09:07:44] (.Hewlett-Packard Co. - HP LaserJet Pro MFP M521 Fax Driver.) -- C:\WINDOWS\Installer\191f72bd.msi [5812224] =>.Hewlett-Packard Co.
[MD5.13CECE13542AE8BD977696DE4428608D] [WIS][2012/07/19 14:59:52] (.Hewlett-Packard Company - HP Product FWUpdater.) -- C:\WINDOWS\Installer\191f72c1.msi [1884160] =>.Hewlett-Packard Company
[MD5.63FCF4578A1097ACAECE09E452FFBA8F] [WIS][2015/03/17 05:52:49] (.Adobe Systems Incorporated.) -- C:\WINDOWS\Installer\1941184d.msi [2803200] =>.Adobe Systems Incorporated
[MD5.BBBA0BA814B2E30AAA0B77C60AD16848] [WIS][2020/12/02 10:49:03] (.Adobe Systems Incorporated - Adobe ARM Installer.) -- C:\WINDOWS\Installer\1a116273.msi [987136] =>.Adobe Systems Incorporated
[MD5.375324ACA01886EEB28A5B9F8B2CFEE7] [WIS][2016/10/06 12:53:06] (.NVIDIA Corporation - Install/UnInstall PhysX Driver + Engines: 2.) -- C:\WINDOWS\Installer\1a4d60b3.msi [26969088] =>.NVIDIA Corporation
[MD5.5B347879852B0B99B685AC4C3396CC0D] [WIS][2016/10/31 12:41:34] (.AxCrypt AB - AxCrypt 2.1.1481.0.) -- C:\WINDOWS\Installer\2f51d8b.msi [3182592] =>.AxCrypt AB
[MD5.1905B09343458611D425B878D952F244] [WIS][2019/09/10 14:30:59] (.Dropbox, Inc. - Dropbox Update Helper.) -- C:\WINDOWS\Installer\3dbdee90.msi [31232] =>.Dropbox, Inc.
[MD5.00D01757986F9699ED1776192B23879B] [WIS][2020/12/09 10:39:05] (.Google LLC - Google Update Helper.) -- C:\WINDOWS\Installer\a6a5774.msi [40960] =>.Google LLC
[MD5.2BF0093E60C2D00175DD9F550D900CB7] [WIS][2017/08/07 05:20:05] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\168fc1.msp [70610944] =>.SUP.Obsolete.Adobe
[MD5.B88274DA8D68D49732CC28A328885C98] [WIS][2020/11/23 07:11:53] (.Adobe Inc..) -- C:\WINDOWS\Installer\1a1162ca.msp [6557696] =>.Adobe Inc.
[MD5.E3869EFD0836C950E46B02D3CBC67184] [WIS][2017/01/09 00:41:00] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\1e63600.msp [25853952] =>.SUP.Obsolete.Adobe
[MD5.CECF2A7991F74C858965EA972A43CE3F] [WIS][2017/04/10 02:34:32] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\2130368.msp [57815040] =>.SUP.Obsolete.Adobe
[MD5.72C91237F7C7A0527FA5F0752CF81A66] [WIS][2017/01/19 07:28:55] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\27991e5f.msp [1937408] =>.SUP.Obsolete.Adobe
[MD5.6CEDDFCEEA7D6AED2C9E892D85B1F302] [WIS][2020/05/29 22:49:12] (.Adobe Inc..) -- C:\WINDOWS\Installer\297b67.msp [244396032] =>.Adobe Inc.
[MD5.141F4ADB491F751F557E2764EB130D49] [WIS][2016/08/02 08:49:14] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\2ab8be16.msp [71073792] =>.SUP.Obsolete.Adobe
[MD5.63B461B17D63F25E40896EB92C900956] [WIS][2019/12/09 05:08:15] (.Adobe Inc..) -- C:\WINDOWS\Installer\2d771220.msp [241102848] =>.Adobe Inc.
[MD5.0762EDB0E4C8D62A4328C3360BC7AD2C] [WIS][2017/07/11 01:57:12] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\31aa4106.msp [1732608] =>.SUP.Obsolete.Adobe
[MD5.B34F2399D4DD3031176F26CDBB1A3FF9] [WIS][2020/10/22 21:56:12] (.Adobe Inc..) -- C:\WINDOWS\Installer\3d90a02e.msp [246079488] =>.Adobe Inc.
[MD5.F767152C881F505C5BBAC71A825C1263] [WIS][2017/02/21 09:33:51] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\5072d38.msp [12845056] =>.SUP.Obsolete.Adobe
[MD5.77AB51250501ADDD4D491DECDB6121FD] [WIS][2017/08/28 13:40:46] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\5b074fcc.msp [2424832] =>.SUP.Obsolete.Adobe
[MD5.3404522672187AD49AD74AEC689075C0] [WIS][2019/02/20 09:28:35] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\9cbd150.msp [228925440] =>.SUP.Obsolete.Adobe
[MD5.BCC43969BE02109C8AC7141C7C3CB9CA] [WIS][2017/08/11 07:04:59] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\a3898.msp [2031616] =>.SUP.Obsolete.Adobe
[MD5.11F7E4FF1AEFD307E111CA25022CD840] [WIS][2020/12/09 08:35:08] (.Adobe Inc..) -- C:\WINDOWS\Installer\a90cac3.msp [3039232] =>.Adobe Inc.
[MD5.339631DF934AFC2BE35E2B27A6F7DB06] [WIS][2016/11/03 04:25:06] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\b1e4cc4.msp [1642496] =>.SUP.Obsolete.Adobe
[MD5.BCD625BA9A27EB27FECE6352AD3196E3] [WIS][2016/06/02 01:48:52] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\c97bcc.msp [69611520] =>.SUP.Obsolete.Adobe
[MD5.4D64DE5B41C39FA6192C22CBCD826FBA] [WIS][2016/10/10 04:29:03] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\d1d716.msp [36499456] =>.SUP.Obsolete.Adobe
[MD5.04B537B3AB3D8FD3121C2F07CB853532] [WIS][2018/02/23 10:25:32] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\dec746f.msp [103350272] =>.SUP.Obsolete.Adobe

---\\ FEATURE CONTROL. (877) - 3s
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:GOM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:mbamtray.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:mbam.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]eek.pngutlook.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSREC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]eek.pngutlook.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]stick_out_tongue.pngowerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WARN_ON_SEC_CERT_REV_FAILED]:mbam.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Wordconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]stick_out_tongue.pngOWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]stick_out_tongue.pngPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]stick_out_tongue.pngresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]stick_out_tongue.pngrevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]stick_out_tongue.pngrotocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]big_green.pngW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]big_green.pngWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Wordconv.exe =>.Legitimate

---\\ Observador dos acontecimentos (89) - 65s

Application.Error: ESENT (1870)
~Numéro: 115918
~Date: 01/15/2021 09:34:26 AM
~ID: 455
~Description: %1 (%2) %3Erro %5 ao abrir o arquivo de log %4.
~Suggestion: Créer un dossier C:\Windows\system32\config\systemprofile\AppData\Local\TileDataLayer\Database

Application.Error: SecurityCenter (86)
~Numéro: 115911
~Date: 01/15/2021 09:32:34 AM
~ID: 17
~Description: A Central de Segurança não validou o chamador com o erro %1.
~Suggestion: Aucune

Application.Error: Software Protection Platform Service (158)
~Numéro: 115890
~Date: 01/15/2021 09:29:40 AM
~ID: 8198
~Description: Falha na Ativação de Licença (slui.exe). Código de erro: hr=0xC004F074 Argumento de linha de comando: RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f58

Application.Error: VSS (15)
~Numéro: 115761
~Date: 01/14/2021 07:48:36 PM
~ID: 8193
~Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao chamar a rotina %1. hr = %2. Operação: Executando Operação AssíncronaContexto: Estado Atual: DoSnapshotSet
~Suggestion: Utiliser la procédure de reconstruction du VSS

Application.Warning: Microsoft-Windows-System-Restore (1)
~Numéro: 115622
~Date: 01/14/2021 09:54:19 AM
~ID: 8303
~Description: Scoping unsuccessful for shadowcopy %1 with error %2.
~Suggestion: Exécuter la commande chkdsk / f

Application.Error: Application Error (6)
~Numéro: 114983
~Date: 01/12/2021 06:03:53 PM
~ID: 1000
~Description: Nome do aplicativo com falha: %1, versão: %2, carimbo de data/hora: 0x5ea37cc6 Nome do módulo com falha: %4, versão: %5, carimbo de data/hora: 0xb29ecf52 Código de exceção: 0xc0000374 Deslocamento da falha: 0x00000000000f9229 ID do processo com falha
~Suggestion: Réparer ou réinstaller l'application.

Application.Error: Application Hang (3)
~Numéro: 114116
~Date: 01/02/2021 10:36:00 PM
~ID: 1002
~Description: O programa %1 versão %2 parou de interagir com o Windows e foi fechado. Para ver se mais informações sobre o problema estão disponíveis, verifique o histórico de problemas no painel de controle Segurança e Manutenção. ID do Processo: 1fa8 Hora de I
~Suggestion: Essayer les commandes suivantes ipconfig /release et ipconfig / renew.

System.Warning: DCOM (277)
~Numéro: 14626
~Date: 01/15/2021 09:29:12 AM
~ID: 10016
~Description: específico do aplicativoLocalIniciarWindows.SecurityCenter.WscBrokerManagerNão DisponívelAUTORIDADE NTSISTEMAS-1-5-18LocalHost (Usando LRPC)Não DisponívelNão Disponível
~Suggestion: Vérifier les autorisations pour l'accès DCOM

System.Error: Service Control Manager (72)
~Numéro: 14617
~Date: 01/15/2021 09:27:17 AM
~ID: 7023
~Description: O serviço %1 terminou com o erro: %%31

System.Error: EventLog (3)
~Numéro: 14581
~Date: 01/15/2021 09:26:58 AM
~ID: 6008
~Description: O desligamento do sistema que ocorreu às %1 do dia %2 não era esperado.

System.Error: Microsoft-Windows-Kernel-Boot (1)
~Numéro: 14571
~Date: 01/15/2021 09:26:17 AM
~ID: 29
~Description: 3221225684Ocorrência de erro fatal em processamento de dados de restauração.

System.Warning: Microsoft-Windows-DNS-Client (61)
~Numéro: 14567
~Date: 01/14/2021 09:21:14 PM
~ID: 1014
~Description: A resolução de nome para o nome %1 expirou depois que nenhum dos servidores DNS configurados respondeu.
~Suggestion: https://social.technet.microsoft.com/wiki/contents/articles/3336.event-id-1014-microsoft-windows-dns-client.aspx

System.Warning: Microsoft-Windows-Time-Service (6)
~Numéro: 14007
~Date: 01/12/2021 05:58:03 PM
~ID: 134
~Description: O NtpClient não conseguiu definir um mesmo nível manual para ser usado como fonte de tempo devido a um erro de resolução de DNS em '%3'. O NtpClient fará nova tentativa em %2 minutos e, depois disso, dobrará o intervalo para uma nova tentativa. Erro:
~Suggestion: Resynchroniser le client avec l'homologue de source de temps

System.Warning: cdrom (8)
~Numéro: 13887
~Date: 01/10/2021 06:54:51 PM
~ID: 51
~Description: Erro detectado no dispositivo %1 durante uma operação de paginação.

System.Warning: BTHUSB (47)
~Numéro: 13259
~Date: 12/24/2020 05:46:38 PM
~ID: 34
~Description: O adaptador local não dá suporte a um estado de controlador de baixo consumo importante para compatibilidade com modo periférico. O valor mínimo necessário de máscara de estado com suporte é %2; valor obtido: %3. A funcionalidade de periférico de bai

System.Error: Microsoft-Windows-HAL (1)
~Numéro: 13039
~Date: 12/21/2020 04:27:23 PM
~ID: 13
~Description: O temporizador watchdog do sistema foi disparado.

---\\ Scâner Aditional (68) - 18s
C:\WINDOWS\Installer\168fc1.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\1e63600.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2130368.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\27991e5f.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2ab8be16.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\31aa4106.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5072d38.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5b074fcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\9cbd150.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\a3898.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\b1e4cc4.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\c97bcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\d1d716.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\dec746f.msp =>.SUP.Obsolete.Adobe
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Games\Alan Wake Complete Collection\Alan Wake's American Nightmare\alan_wakes_american_nightmare.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.ApplicationCompany =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\Resident Evil Revelations\rerev.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\Resident Evil HD Remaster\bhd.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Child of Light - Yello Trainer.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Cheat Engine 7.1\Cheat Engine.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Games\Alan Wake Complete Collection\Alan Wake\alanwake.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Un_.EXE.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\tew_executioner_v1.7_trn.EXE.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\GOG Games\Unepic\unepic.exe.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\tew_assignmet_v1.0_trn.EXE.FriendlyAppName =>.Unsigned
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Games\Alan Wake Complete Collection\Alan Wake's American Nightmare\alan_wakes_american_nightmare.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.ApplicationCompany =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\Resident Evil Revelations\rerev.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\Resident Evil HD Remaster\bhd.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Child of Light - Yello Trainer.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Cheat Engine 7.1\Cheat Engine.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Games\Alan Wake Complete Collection\Alan Wake\alanwake.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Un_.EXE.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\tew_executioner_v1.7_trn.EXE.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\GOG Games\Unepic\unepic.exe.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\tew_assignmet_v1.0_trn.EXE.FriendlyAppName =>.Unsigned
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe.FriendlyAppName =>.Unsigned

---\\ Resumo dos elementos encontrados na sua estação de trabalho (4) - 0s
https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.Obsolete.Adobe
https://nicolascoolman.eu/forum/Topic/warning-eventlogapp-evenement-dapplication/ =>Warning.EventLogApp
https://nicolascoolman.eu/forum/Topic/warning-eventlogsys-evenement-systeme/ =>Warning.EventLogSys
https://nicolascoolman.eu/forum/Topic/orphan-muicache-logiciel-potentiellement-superflu-lps/ =>.SUP.Orphan.MUICache

---\\
[00CC2413C6F7315CA6CC837FD2E857CC6A] [19/10/2018] (.AVB Disc Soft, SIA.) - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe =>.AVB Disc Soft, SIA
[00CC2413C6F7315CA6CC837FD2E857CC6A] [19/10/2018] (.AVB Disc Soft, SIA.) - C:\Program Files\DAEMON Tools Lite\DTAgent.exe =>.AVB Disc Soft, SIA
[00CC2413C6F7315CA6CC837FD2E857CC6A] [19/10/2018] (.AVB Disc Soft, SIA.) - C:\Program Files\DAEMON Tools Lite\DTLauncher.exe =>.AVB Disc Soft, SIA
[00CC2413C6F7315CA6CC837FD2E857CC6A] [19/10/2018] (.AVB Disc Soft, SIA.) - C:\Program Files\DAEMON Tools Lite\uninst.exe =>.AVB Disc Soft, SIA
[00FE46A10AD94269C3DD225C13645352E4] [31/05/2016] (.win.rar GmbH.) - C:\Program Files\WinRAR\Ace32Loader.exe =>.win.rar GmbH
[00FE46A10AD94269C3DD225C13645352E4] [31/05/2016] (.win.rar GmbH.) - C:\Program Files\WinRAR\uninstall.exe =>.win.rar GmbH
[017CA19B5859E83F44D874C1CE506E6D] [27/09/2016] (.Dropbox, Inc.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc
[02FA994D660DE659EE9037ECB437D766] [06/01/2021] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [06/01/2021] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\CCUpdate.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [06/01/2021] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\uninst.exe =>.Piriform Software Ltd
[06F04788031055D31DEFFEFCD026D6C5] [04/09/2018] (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated
[077A4C29E67926572A64DFD26224FC8D] [04/06/2019] (.Dropbox, Inc.) - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll =>.Dropbox, Inc
[077A4C29E67926572A64DFD26224FC8D] [04/12/2019] (.Dropbox, Inc.) - C:\Program Files (x86)\Dropbox\Client\Dropbox.exe =>.Dropbox, Inc
[077A4C29E67926572A64DFD26224FC8D] [04/12/2019] (.Dropbox, Inc.) - C:\Program Files (x86)\Dropbox\Client\DropboxUninstaller.exe =>.Dropbox, Inc
[077A4C29E67926572A64DFD26224FC8D] [04/12/2019] (.Dropbox, Inc.) - C:\WINDOWS\System32\DbxSvc.exe =>.Dropbox, Inc
[08105595FD145FC9F8E0594C7F0249B0] [12/01/2021] (.Bitdefender SRL.) - C:\WINDOWS\System32\drivers\avchv.sys =>.Bitdefender SRL
[09E65AD807B8497B0749D41568D626D0] [03/05/2016] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation
[09E65AD807B8497B0749D41568D626D0] [03/05/2016] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
[09E65AD807B8497B0749D41568D626D0] [03/05/2016] (.Mozilla Corporation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation
[0C15BE4A15BB0903C901B1D6C265302F] [05/01/2021] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\elevation_service.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [05/01/2021] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [12/01/2021] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\Installer\chrmstp.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [12/01/2021] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\Installer\setup.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [13/01/2021] (.Google LLC.) - C:\Users\Ramon.NOTEBOOK\AppData\Local\Google\Chrome\User Data\SwReporter\87.250.200\software_reporter_tool.exe =>.Google LLC
[0DDFAC95C5B238B54C88AF81C85D5EB4] [15/06/2012] (.Remedy Entertainment Ltd..) - C:\Games\Alan Wake Complete Collection\Alan Wake\alanwake.exe =>.Remedy Entertainment Ltd.
[0EE3F1C8F451CBF21203341A53F23E71] [03/11/2020] (.Adobe Inc..) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Inc.
[0EE3F1C8F451CBF21203341A53F23E71] [07/12/2020] (.Adobe Inc..) - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Inc.
[0EE3F1C8F451CBF21203341A53F23E71] [22/10/2020] (.Adobe Inc..) - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroBroker.exe =>.Adobe Inc.
[0FE7C5F7C10716F0A4EB0D4B4D581371] [31/07/2014] (.Google Inc.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe =>.Google Inc
[112172E6B04266BB4059BFEF636CF8F452A0] [17/10/2016] (.Disc Soft Ltd.) - C:\WINDOWS\System32\drivers\dtlitescsibus.sys =>.Disc Soft Ltd
[112172E6B04266BB4059BFEF636CF8F452A0] [17/10/2016] (.Disc Soft Ltd.) - C:\WINDOWS\System32\drivers\dtliteusbbus.sys =>.Disc Soft Ltd
[1121C8E7AC6869E3322CCE5E3451CF9142D9] [16/11/2016] (.Cheat Engine.) - C:\Program Files (x86)\Cheat Engine 6.6\unins000.exe =>.Cheat Engine
[12EDCAB8B492485728244AA0] [08/10/2016] (.Cheat Engine.) - C:\Program Files (x86)\Cheat Engine 6.6\cheatengine-x86_64.exe =>.Cheat Engine
[13222A5DCCF716DF5AF9C87084412DD9] [03/07/2015] (.Realtek Semiconductor Corp.) - C:\WINDOWS\System32\Drivers\RtsUer.sys =>.Realtek Semiconductor Corp
[13222A5DCCF716DF5AF9C87084412DD9] [09/07/2015] (.Realtek Semiconductor Corp.) - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
[13222A5DCCF716DF5AF9C87084412DD9] [09/07/2015] (.Realtek Semiconductor Corp.) - C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe =>.Realtek Semiconductor Corp
[13222A5DCCF716DF5AF9C87084412DD9] [09/07/2015] (.Realtek Semiconductor Corp.) - C:\WINDOWS\System32\drivers\RTKVHD64.sys =>.Realtek Semiconductor Corp
[1D9FF0CFF14FE700963E52F6CDACF575] [05/08/2015] (.Synaptics Incorporated.) - C:\WINDOWS\System32\DRIVERS\SynRMIHID.sys =>.Synaptics Incorporated
[26181CEDF2C113E16AC74820DF7A38A3] [05/09/2016] (.Samsung Electronics CO., LTD..) - C:\WINDOWS\System32\DRIVERS\ssudbus.sys =>.Samsung Electronics CO., LTD.
[26181CEDF2C113E16AC74820DF7A38A3] [05/09/2016] (.Samsung Electronics CO., LTD..) - C:\WINDOWS\System32\DRIVERS\ssudmdm.sys =>.Samsung Electronics CO., LTD.
[2912C70C9A2B8A3EF6F6074662D68B8D] [13/10/2015] (.Google Inc.) - C:\Program Files (x86)\Google\Picasa3\Picasa3.exe =>.Google Inc
[2912C70C9A2B8A3EF6F6074662D68B8D] [13/10/2015] (.Google Inc.) - C:\Program Files (x86)\Google\Picasa3\Uninstall.exe =>.Google Inc
[330000B6712F575E402CF8708400020000B671] [04/06/2015] (.Intel(R) Code Signing External.) - C:\Windows\system32\drivers\semav6msr64.sys =>.Intel(R) Code Signing External
[330000B85395C584DD5249B00800020000B853] [12/05/2016] (.Intel(R) OWR.) - C:\WINDOWS\System32\drivers\IntcDAud.sys =>.Intel(R) OWR
[330000BB0B8823E10D1669124600020000BB0B] [25/09/2017] (.Intel(R) pGFX.) - C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\Setup.exe =>.Intel(R) pGFX
[330000BB0B8823E10D1669124600020000BB0B] [25/09/2017] (.Intel(R) pGFX.) - C:\WINDOWS\System32\DRIVERS\igdkmd64.sys =>.Intel(R) pGFX
[330000BB0B8823E10D1669124600020000BB0B] [25/09/2017] (.Intel(R) pGFX.) - C:\WINDOWS\System32\igfxCUIService.exe =>.Intel(R) pGFX
[330000BB0B8823E10D1669124600020000BB0B] [25/09/2017] (.Intel(R) pGFX.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel(R) pGFX
[3DB29A3651F3F5E49CE079D283957630] [02/03/2016] (.Bitdefender SRL.) - C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe =>.Bitdefender SRL
[3DB29A3651F3F5E49CE079D283957630] [02/03/2016] (.Bitdefender SRL.) - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe =>.Bitdefender SRL
[3DB29A3651F3F5E49CE079D283957630] [02/03/2016] (.Bitdefender SRL.) - C:\Program Files\Bitdefender\Antivirus Free Edition\GzShellIntegration.dll =>.Bitdefender SRL
[3DB29A3651F3F5E49CE079D283957630] [04/09/2013] (.Bitdefender SRL.) - C:\Program Files\Bitdefender\Antivirus Free Edition\Install\Installer.exe =>.Bitdefender SRL
[411239DA46A29C98B8A15077] [13/04/2020] (.Cheat Engine.) - C:\Program Files\Cheat Engine 7.1\Cheat Engine.exe =>.Cheat Engine
[411239DA46A29C98B8A15077] [16/07/2020] (.Cheat Engine.) - C:\Program Files\Cheat Engine 7.1\unins000.exe =>.Cheat Engine
[425A08D469922E9DF01CD8F6BA3AFA0C] [30/06/2012] (.Hewlett Packard.) - C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\Bin\HPScan.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\bin\DigitalWizards.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\bin\EWSProxy.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\bin\FaxApplications.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files (x86)\HP\HP LaserJet Pro MFP M521\Bin\HPNetworkCommunicator.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files\HP\HP LaserJet Pro MFP M521\bin\FaxPrinterUtility.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files\HP\HP LaserJet Pro MFP M521\Bin\HPNetworkCommunicator.exe =>.Hewlett Packard
[44239C2187EFAE7BA9F3CD89C4FE9D84] [01/11/2012] (.Hewlett Packard.) - C:\Program Files\HP\HP LaserJet Pro MFP M521\bin\SendAFax.exe =>.Hewlett Packard
[44BC63EA9D7FB68CBCD9101F391CA145] [07/03/2012] (.Hewlett-Packard Company.) - C:\Program Files (x86)\HP\csiInstaller\8c0c6b8e-5f52-48bc-afe5-e43403a7d16e\Setup.exe =>.Hewlett-Packard Company
[44BC63EA9D7FB68CBCD9101F391CA145] [19/10/2012] (.Hewlett-Packard Company.) - C:\Program Files (x86)\HP\csiInstaller\8c0c6b8e-5f52-48bc-afe5-e43403a7d16e\Installer\hpbcsiInstaller.exe =>.Hewlett-Packard Company
[470F76D35837A1ADDCC5FFA3085A6FC2] [29/11/2012] (.Hewlett-Packard Company.) - C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe =>.Hewlett-Packard Company
[491F09787113578567BB451222AA64D1] [02/07/2013] (.Bitdefender SRL.) - C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys =>.Bitdefender SRL
[491F09787113578567BB451222AA64D1] [17/04/2013] (.Bitdefender SRL.) - C:\WINDOWS\System32\drivers\avc3.sys =>.Bitdefender SRL
[491F09787113578567BB451222AA64D1] [17/04/2013] (.Bitdefender SRL.) - C:\WINDOWS\System32\DRIVERS\avckf.sys =>.Bitdefender SRL
[491F09787113578567BB451222AA64D1] [22/04/2013] (.Bitdefender SRL.) - C:\WINDOWS\System32\DRIVERS\gzflt.sys =>.Bitdefender SRL
[491F09787113578567BB451222AA64D1] [28/05/2013] (.Bitdefender SRL.) - C:\WINDOWS\System32\DRIVERS\trufos.sys =>.Bitdefender SRL
[4C40DBA5F988FAE57A57D6457495F98B] [12/08/2016] (.Google Inc.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
[4F58FC05426CC4B65DBC0C2C2E3AF304] [15/06/2020] (.GRETECH CORPORATION.) - C:\Program Files (x86)\GRETECH\GOMPlayer\Uninstall.exe =>.Not verified
[4F58FC05426CC4B65DBC0C2C2E3AF304] [17/06/2020] (.GRETECH CORPORATION.) - C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe =>.Not verified
[593BC95C7932A287289F844B482665FD] [07/12/2016] (.AxCrypt AB.) - C:\ProgramData\Package Cache\{18db8d8e-e8a9-4911-a0bb-978f5341daeb}\AxCrypt.NET.Bootstrapper.exe =>.AxCrypt AB
[5B8E8336B71D049D3C30290622AFDCB9] [22/03/2013] (.QLOC S.A..) - C:\Program Files (x86)\Resident Evil 6\BH6.exe =>.QLOC S.A.
[7FE63AB8AB9D36964BC29EAD7641180A] [16/08/2016] (.NGO.) - C:\WINDOWS\System32\DRIVERS\usb2ser.sys =>.NGO

~ Unselected Options: WR, O38, O82,
~ End of the scan, 8249 items in 07mn47s (3024)(0)

joram disse:
/!\ Boa Noite! R. Moran /!\



Faça com a ferramenta ZHPDiag,novo scan e poste o relatório.

Ps: Não serve o antigo!

E o BitDefender,ainda detecta a ameaça?



[]s
R. Moran
"Podemos facilmente perdoar uma criança que tem medo do escuro; a real tragédia da vida é quando os homens têm medo da luz."
Platão
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#12 Por joram
15/01/2021 - 12:34
/!\ Boa Tarde! R. Moran /!\

> Baixe: < Imagem >
http://www.commentcamarche.net/download/telecharger-34102185-zhpfix

> Ou aqui!
> Estando na página,clique: "Télécharger"
> Salve-o ao desktop!
> Instale-o,clicando em: Suivant >> Suivant >>...>> Suivant >> Suivant >> Installer >> Terminer
Ps: Caso surja uma mensagem do Windows com a frase "Deseja permitir que o programa de um fornecedor desconhecido faça alterações neste computador?" Clique "Sim"

> Execute este script na ferramenta ZHPFix.

"script zhpfix"
Script ZHPFix
EmptyPrefetch
EmptyClsid
EmptyFlash
EmptyTemp
FirewallRaz
ShortcutFix
Ifeofix
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\.DEFAULT\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\Chromium =>.Chromium

C:\WINDOWS\Installer\168fc1.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\1e63600.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2130368.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\27991e5f.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2ab8be16.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\31aa4106.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5072d38.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5b074fcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\9cbd150.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\a3898.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\b1e4cc4.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\c97bcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\d1d716.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\dec746f.msp =>.SUP.Obsolete.Adobe


> Selecione e copie estas informações que estão em vermelho,para o Bloco de Notas.
> Com o Bloco de Notas aberto,faça: ctrl+a >> ctrl+c ( Selecionar e Copiar )
> À seguir,minimize o Bloco de Notas.

> Abra a ferramenta ZHPFix. < Imagem >

Imagem

> Clique IMPORTAÇÃO >> OK.
> Ao clicar "OK",verifique se o campo está limpo para que receba,somente,as informações do script.
> Não encontrando anormalidades,clique "GO".

Imagem

> Ou,clique CONFIGURAR >> Personalizar.
> Cole as informações contidas no Bloco de Notas,ao campo da ferramenta.
> Clique "GO" >> Oui >> Oui
> Poste o relatório! (C:\Users\Usuário\AppData\Roaming\ZHP\ZHPFix[R1].txt)

< Peço aos visitantes que não utilizem este script em seus computadores,sob risco de danos aos mesmos! >

[]s
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas
#13 Por R. Moran
19/01/2021 - 10:08
joram disse:
/!\ Boa Tarde! R. Moran /!\

> Baixe: < Imagem >

> Ou aqui!
> Estando na página,clique: "Télécharger"
> Salve-o ao desktop!
> Instale-o,clicando em: Suivant >> Suivant >>...>> Suivant >> Suivant >> Installer >> Terminer

> Execute este script na ferramenta ZHPFix.

"script zhpfix"
Script ZHPFix
EmptyPrefetch
EmptyClsid
EmptyFlash
EmptyTemp
FirewallRaz
ShortcutFix
Ifeofix
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\.DEFAULT\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\Chromium =>.Chromium

C:\WINDOWS\Installer\168fc1.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\1e63600.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2130368.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\27991e5f.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2ab8be16.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\31aa4106.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5072d38.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5b074fcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\9cbd150.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\a3898.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\b1e4cc4.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\c97bcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\d1d716.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\dec746f.msp =>.SUP.Obsolete.Adobe


> Selecione e copie estas informações que estão em vermelho,para o Bloco de Notas.
> Com o Bloco de Notas aberto,faça: ctrl+a >> ctrl+c ( Selecionar e Copiar )
> À seguir,minimize o Bloco de Notas.

> Abra a ferramenta ZHPFix. < Imagem >

Imagem

> Clique IMPORTAÇÃO >> OK.
> Ao clicar "OK",verifique se o campo está limpo para que receba,somente,as informações do script.
> Não encontrando anormalidades,clique "GO".

Imagem

> Ou,clique CONFIGURAR >> Personalizar.
> Cole as informações contidas no Bloco de Notas,ao campo da ferramenta.
> Clique "GO" >> Oui >> Oui
> Poste o relatório! (C:\Users\Usuário\AppData\Roaming\ZHP\ZHPFix[R1].txt)

< Peço aos visitantes que não utilizem este script em seus computadores,sob risco de danos aos mesmos! >

[]s

Bom dia, Joram. Desculpe a demora em responder, pois tive que fazer uma viagem essa semana e onde estava o sinal de internet era precário. Porém desde ontem venho tentando instalar o ZHPFix e ao clicar em "Télécharger", sou direcionado para uma página com mensagem de "Erro 404 - não encontrado". Em baixo vem outra mensagem: "O arquivo necessário não foi encontrado. Pode ser um erro técnico. Tente novamente mais tarde. Se você não conseguir acessar o arquivo após várias tentativas, significa que ele foi excluído."
Hoje estou tentando novamente e a mesma mensagem se repete. Será que a ferramenta foi excluída? Aguardo suas orientações. Grato
R. Moran
"Podemos facilmente perdoar uma criança que tem medo do escuro; a real tragédia da vida é quando os homens têm medo da luz."
Platão
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#14 Por joram
19/01/2021 - 14:53
/!\ Boa Tarde! R. Moran /!\

> Foi mesmo erro técnico e o link está quebrado!
> E a ferramenta apresentou atualização em seu Modus Operandi,inclusive na escrita do script.
> Portanto,ignore o anterior!

> Baixe: < Imagem >
https://nicolascoolman.eu/download/zhpfix-script-manager/#

> Estando na página,clique: "TÉLÉCHARGEZ ICI"
> Salve-o ao desktop!

Imagem

> Abra a ferramenta e clique "Eu".

Imagem

> Cole este script ,que está no spoiler,no campo da ferramenta ZHPFix.
> Clique em "colar um script".

[spoiler]Start::
EmptyTemp
EmptyFlash
EmptyCLSID
EmptyTracing
EmptyRecycle
EmptyPrefetch
CreateRestorePoint
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\.DEFAULT\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\Chromium =>.Chromium
C:\WINDOWS\Installer\168fc1.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\1e63600.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2130368.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\27991e5f.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2ab8be16.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\31aa4106.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5072d38.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5b074fcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\9cbd150.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\a3898.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\b1e4cc4.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\c97bcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\d1d716.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\dec746f.msp =>.SUP.Obsolete.Adobe
End::
[/spoiler]

Imagem

> Após colar o script no campo da ferramenta,clique no ícone da "vassourinha".
> Ao concluir,poste o relatório! (C:\Users\Usuário\AppData\Roaming\ZHP\ZHPFix[R1].txt)

[]s
R. Moran
R. Moran Membro Senior Registrado
92 Mensagens 60 Curtidas
#15 Por R. Moran
19/01/2021 - 21:35
joram disse:
/!\ Boa Tarde! R. Moran /!\

> Foi mesmo erro técnico e o link está quebrado!
> E a ferramenta apresentou atualização em seu Modus Operandi,inclusive na escrita do script.
> Portanto,ignore o anterior!

> Baixe: < Imagem >

> Estando na página,clique: "TÉLÉCHARGEZ ICI"
> Salve-o ao desktop!

Imagem

> Abra a ferramenta e clique "Eu".

Imagem

> Cole este script ,que está no spoiler,no campo da ferramenta ZHPFix.
> Clique em "colar um script".

[spoiler]Start::
EmptyTemp
EmptyFlash
EmptyCLSID
EmptyTracing
EmptyRecycle
EmptyPrefetch
CreateRestorePoint
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\.DEFAULT\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\Chromium =>.Chromium
C:\WINDOWS\Installer\168fc1.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\1e63600.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2130368.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\27991e5f.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2ab8be16.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\31aa4106.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5072d38.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5b074fcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\9cbd150.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\a3898.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\b1e4cc4.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\c97bcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\d1d716.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\dec746f.msp =>.SUP.Obsolete.Adobe
End::
[/spoiler]

Imagem

> Após colar o script no campo da ferramenta,clique no ícone da "vassourinha".
> Ao concluir,poste o relatório! (C:\Users\Usuário\AppData\Roaming\ZHP\ZHPFix[R1].txt)

[]s


Boa noite, Joram. Segue relatório:
"ZHPFix v2020"

~ ZHPFix v2020.11.29.258 by Nicolas Coolman (2020/11/29)
~ Run by Ramon (Administrator) (19/01/2021 21:25:29)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Certificate ZHPFix: Legal
~ State version : Versão OK
~ Report : C:\Users\Ramon.NOTEBOOK\Desktop\ZHPFix.txt
~ Quarantine : HKCU\SOFTWARE\ZHP\ZHPFix\Quarantine\
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 18362)



---\\ SCRIPT. (64)
Start::
EmptyTemp
EmptyFlash
EmptyCLSID
EmptyTracing
EmptyRecycle
EmptyPrefetch
CreateRestorePoint
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:E:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:F:\setup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
[HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName =>.SUP.Orphan.MUICache
HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\.DEFAULT\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Baixaki =>.Baixaki
HKCU\SOFTWARE\Chromium =>.Chromium
C:\WINDOWS\Installer\168fc1.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\1e63600.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2130368.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\27991e5f.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\2ab8be16.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\31aa4106.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5072d38.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\5b074fcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\9cbd150.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\a3898.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\b1e4cc4.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\c97bcc.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\d1d716.msp =>.SUP.Obsolete.Adobe
C:\WINDOWS\Installer\dec746f.msp =>.SUP.Obsolete.Adobe
End::


---\\ SOFTWARE. (0)


---\\ SERVICO. (0)


---\\ TAREFA agendada. (0)


---\\ NAVEGADOR de Internet. (0)


---\\ EXPLORADOR (pastas, ficheiros). (55)
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\aria-debug-7480.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\gziface.log
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\gziface1.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-10228.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-10640.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-124.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-1372.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-2264.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-3156.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-3872.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-4404.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-4512.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-4912.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-4940.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-5732.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-6704.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8140.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8292.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8312.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8496.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8516.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8532.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-8824.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-9184.log
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\mat-debug-9724.log
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\0c6e2183-710c-4b90-aab2-6677306cb973.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\2846cf98-a0ba-437c-8cb9-44b1552c4f13.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\3515220d-2023-47a5-ad88-8c972d9555f1.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\5188cab4-dc35-454d-9805-4f9c2c9f5023.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\5677014c-6a5a-4b64-802b-e4749f09f0ca.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\b6238c54-52f7-4fc4-bf69-33cc494087d2.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\c01b9d12-ec2b-4900-8ca8-b99bd1f7bb7d.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\dbf0c49d-c55f-4e5a-8fa2-7b61133742f3.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\f33e3d90-804f-440c-8012-6f91a9b3d699.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\f8d18909-7990-43bd-a0a8-73b98fb35455.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\f9c469b4-56eb-47bb-b0f3-a2395b60130d.tmp
EXCLUIDO Reboot Arquivo Temp^: C:\Users\RAMON~1.NOT\AppData\Local\Temp\RDR7D98.tmp
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\wct7239.tmp
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\wct89D6.tmp
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\wctB617.tmp
MOVIDO Arquivo Temp: C:\Users\RAMON~1.NOT\AppData\Local\Temp\~DFF97B5A2630DB6A48.TMP
MOVIDO Arquivo : C:\WINDOWS\Installer\168fc1.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\1e63600.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\2130368.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\27991e5f.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\2ab8be16.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\31aa4106.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\5072d38.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\5b074fcc.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\9cbd150.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\a3898.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\b1e4cc4.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\c97bcc.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\d1d716.msp
MOVIDO Arquivo : C:\WINDOWS\Installer\dec746f.msp


---\\ REGISTRO (chaves, valores, dados). (31)
EXCLUIDO Chave: HKU\S-1-5-21-2109982156-1193874355-445741488-1002\SOFTWARE\AvastAdSDK [AvastAdSDK ]
EXCLUIDO Chave: HKU\.DEFAULT\SOFTWARE\Baidu [Baidu ]
EXCLUIDO Chave: HKCU\SOFTWARE\Baixaki [Baixaki ]
EXCLUIDO Chave: HKCU\SOFTWARE\Chromium [Chromium ]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: E:\setup.exe.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: E:\setup.exe.ApplicationCompany [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: F:\setup.exe.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: F:\setup.exe.ApplicationCompany [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Alan Wake Trainer (+13) [Ver 1.06.17.0155] [Update 31.10.2018] [64 Bit] {Baracuda}.EXE.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Age of Empires II Definitive Edition v1.0-Build.33059 Plus 13 Trainer.exe.ApplicationCompany [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\RER 2\Resident Evil Revelations 2 v1.0-v5.00 Plus 20 Trainer.exe.ApplicationCompany [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\TEW\The Evil Within The Consequence ALL DLC Trainer (+8) [ver 1.0.u4_(Update 4)_64 Bit] {Baracuda}.EXE.FriendlyAppName [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: E:\setup.exe.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: E:\setup.exe.ApplicationCompany [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: F:\setup.exe.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: F:\setup.exe.ApplicationCompany [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.FriendlyAppName [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil 6 v1.0 Plus 14 Trainer.exe.ApplicationCompany [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
EXCLUIDO Valor: C:\Users\Ramon.NOTEBOOK\Desktop\Trainer's\Resident Evil Revelations\Resident Evil_Revelations HD v1.0 Plus 11 Trainer.exe.ApplicationCompany [HKU\S-1-5-21-2109982156-1193874355-445741488-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]


---\\ COMANDO. (7)
~ EmptyTemp: pasta Temp local esvaziada parcialmente (41)
~ EmptyFlash: pasta flashplayer vazia.
~ EmptyCSID: pastas CLSID vazias excluídas (0)
~ EmptyTracing: chaves de rastreamento removidas (11)
~ EmptyRecycle: lixeira esvaziada com sucesso.
~ EmptyPrefetch: Arquivos de prebuscador excluídos (233)
CreateRestorePoint: OK


---\\ NAO PROCESSADO. (0)

~ O sistema foi reiniciado.

***** ~ Fim do relatório concluído em 00h03mn19s
R. Moran
"Podemos facilmente perdoar uma criança que tem medo do escuro; a real tragédia da vida é quando os homens têm medo da luz."
Platão
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal