Logo Hardware.com.br
Responder
caedurodrigues
caedurodrigu... Tô em todas Registrado
710 Mensagens 257 Curtidas
#2 Por caedurodrigu...
05/02/2015 - 01:29
Boa noite PEDRAZZI,

  • Baixe: <ZHPDiag ><5fae498c5cd6c951142509fbc9efda13> ( ...Nicolas Coolman)
  • Salve-o no Disco local (C ou D).
  • Desabilite seu antivírus, e execute ZHPDiag.exe para instalar.

    e0baac1fc96e2b6998362b4e757228c9
  • Execute o ícone do pergaminho!

    74bd92827a56ccef3293e039379d6b90
  • Clique na opção "COMPLETA" e aguarde a conclusão.
  • Clique OK e,ao concluir, poste o relatório! ( ZHPDiag.txt )
  • Obs: O relatório por ser extenso deve ser postado em um desses sites:
  • Acesse: <b7cb62cfb007715d3990c0ffc7a9f4ee>
  • Ou acesse:<317c011bca045ff7fc0b26f3766d4d22>
  • Ou anexe-o ao fórum.


Um grande abraço. bom_trabalho.gif
PEDRAZZI
PEDRAZZI Novo Membro Registrado
30 Mensagens 0 Curtidas
#3 Por PEDRAZZI
05/02/2015 - 11:58

~ Relatório do ZHPDiag v2015.2.2.15 - Nicolas Coolman (02/02/2015)
~ Iniciado por IGOR (05/02/2015 01:33:59)
~ Facebook : <a href="https://www.facebook.com/nicolascoolman1" target="_blank">https://www.facebook.com/nicolascoolman1</a>
~ Endereço do Webforum : <a href="'http://forum.nicolascoolman.fr/'" target="_blank">http://forum.nicolascoolman.fr</a>
~ Tradução pelo utilizador
~ Estatuto da versão : Versão atualizada.
~ Lista Branca : Desativado pelo Utilizador
~ Elevação dos Privilégios : OK
~ Controle de Conta de Utilizador : Activate by user


---\\ Navegadores Internet
MSIE: Internet Explorer v11.0.9600.17498
GCIE: Google Chrome v40.0.2214.94 (Defaut)

---\\ Informações sobre os produtos Windows
~ Langage: Portugais
Windows Server License Manager Script : OK
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 8.1 Connected, 64-bit (Build 9600)

---\\ Softwares de proteçao do sistema
Malwarebytes Anti-Malware versão 2.0.4.1028
McAfee LiveSafe – Internet Security v12.8.992
Windows Defender W8 (Deactivate)

---\\ Softwares d'optimização do sistema

---\\ Softwares de partilha do PeerToPeer (P2P)

---\\ Monitoramento dos softwares

---\\ Informações sobre o sistema
~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3990 MB (51% free)
System Restore: Activé (Enable)
System drive C: has 413 GB (91%) free of 451 GB

---\\ Modo de conexão ao sistema
~ Computer Name: IGOR
~ User Name: IGOR
~ All Users Names: IGOR, HomeGroupUser$, Convidado, Administrador,
~ Unselected Option: None
Logged in as Administrator

---\\ As variáveis de ambiente
~ System Unit : C:\
~ %AppZHP% : C:\Users\IGOR\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\IGOR\AppData\Roaming\
~ %Desktop% : C:\Users\IGOR\Desktop\
~ %Favorites% : C:\Users\IGOR\Favorites\
~ %LocalAppData% : C:\Users\IGOR\AppData\Local\
~ %StartMenu% : C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumeração das unidades dos discos
C: Hard drive, Flash drive, Thumb drive (Free 413 Go of 451 Go)
D: CD-ROM drive (Not Inserted)



---\\ Estado do Centro de Segurança do Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 44 Scanned in 00mn 00s



---\\ Pesquisa particular de ficheiros genéricos
[MD5.ACDBE1ED38167C8B01B8F63161BB2CEA] - (.Microsoft Corporation - Windows Explorer.) (.23/08/2014 - 04:48:28.) -- C:\Windows\Explorer.exe [2374784]
[MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Aplicativo de Inicialização do Windows.) (.22/08/2013 - 06:58:29.) -- C:\Windows\System32\Wininit.exe [144384]
[MD5.4AF089160FE082E5EA5C4AA72782DCA2] - (.Microsoft Corporation - Internet Extensions para Win32.) (.21/11/2014 - 22:28:21.) -- C:\Windows\System32\wininet.dll [2358272]
[MD5.306EB21E5B480AE9065EA55AC8C35936] - (.Microsoft Corporation - Aplicativo de Logon do Windows.) (.18/03/2014 - 07:03:12.) -- C:\Windows\System32\Winlogon.exe [562176]
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Biblioteca de Licenciamento de Software.) (.18/03/2014 - 07:03:14.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 00:03:03.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 09:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 08:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 05:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.23/05/2014 - 10:32:49.) -- C:\Windows\system32\Drivers\DfsC.sys [134144]
[MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.24/07/2014 - 08:45:39.) -- C:\Windows\system32\Drivers\HDAudBus.sys [76800]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Driver de porta i8042.) (.22/08/2013 - 08:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.18/03/2014 - 07:03:17.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
[MD5.7A1A3F213CDB3363D179D5014272025D] - (.Microsoft Corporation - Minirdr SMB do Windows NT.) (.30/04/2014 - 03:41:46.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402432]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 08:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.038C77D577900EE39410662478BB0D50] - (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) (.24/07/2014 - 12:07:52.) -- C:\Windows\system32\Drivers\ntfs.sys [2009920]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Driver de porta paralela.) (.22/08/2013 - 08:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 08:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecionador do Dispositivo RDP da Microsoft.) (.18/03/2014 - 06:33:00.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 10:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) (.18/06/2014 - 23:13:36.) -- C:\Windows\system32\Drivers\volsnap.sys [310080]
~ Generic Processes: Scanned in 00mn 05s



---\\ Estatuto dos ficheiros ocultos (Oculto/Total)
~ Mes Favoris (My Favorites) : 1/6
~ Mes Documents (My Documents) : 1/21
~ Mon Bureau (My Desktop) : 0/20
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 00mn 00s



---\\ Processos lançados
[MD5.77590CE0CDEB6BBEE8DC056FEA0B107C] - (.SearchProtect - CmdShell.exe.) -- C:\Program Files (x86)\XTab\cmdshell.exe [48304] [PID.1056] =>PUP.SearchProtect
[MD5.C04D8BC933470B3913E4E3E6C3115793] - (.XTab system - SupHPNot.exe.) -- C:\Program Files (x86)\XTab\HPNotify.exe [673968] [PID.4752]
[MD5.C5D5753F7B1B807FD0A3570F7839CEBD] - (.No owner - HIDRec Application - AVerHID.) -- C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [163840] [PID.4848]
[MD5.AFD4A31A4647810A49AD9ADC00C5C399] - (.AVerMedia TECHNOLOGIES, Inc. - AVerQuick.) -- C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [675840] [PID.4856]
[MD5.FF2CE3EC0F87A69B2F61EF9D89514800] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504] [PID.5648]
[MD5.8DF7F2A9B72B7CA4294BB9E59FEAEFCD] - (.Microsoft Corporation - Host WWA Microsoft.) -- C:\Windows\syswow64\wwahost.exe [514560] [PID.2792]
[MD5.749E4BF1FA6DB8C3F9C2B7F29A544F95] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592] [PID.4716]
[MD5.04603135DD26AEF9A2EDD9E3F4A6755D] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe [1677904] [PID.3780] =>P2P.BitTorrent
[MD5.1F5586FE63F064EC54DF1C32F5030219] - (.Alexander Roshal - WinRAR archiver.) -- C:\Program Files (x86)\WinRAR\WinRAR.exe [1405528] [PID.3196]
[MD5.BE52EDAADE29AC59681B6CD60E257C92] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8158720] [PID.4880]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Arranque,Pesquisa,Extensões (G0,G1,G2)
C:\Users\IGOR\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Pasta de extensão do Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 03s



---\\ Mozilla Firefox, Plugins,Arranque,Pesquisa,Extensões (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@mcafee.com/MSC,version=10] - (...) -- C:\Program Files\mcafee\msc\npMcSnFFPl64.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.0] - (.VideoLAN - VLC media player Web Plugin 2.1.0.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN
~ Firefox Browser: 2 Scanned in 00mn 00s



---\\ Internet Explorer, Arranque, Pesquisa, URLSearchHook( gancho de URL), Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navegador da Internet.) (11.00.9600.17496 (winblue_r5.141121-1500)) -- C:\Windows\SysWOW64\ieframe.dll
~ IE Browser: 17 Scanned in 00mn 00s



---\\ Internet Explorer, Gestão do Proxy (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Análise das linhas F0, F1, F2, F3 - Ficheiros ini, Carregamento Automático de programas
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Redireção do ficheiro Hosts (01)
~ Le fichier hôte est sain (The hosts file is clean) (0)
~ Hosts File: Scanned in 00mn 00s



---\\ Browser Helper Objects do navegador (02)
O2 - BHO: IETabPage Class [64Bits] - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} . (.Thinknice Co. Limited - SupTab setup package.) -- C:\Program Files (x86)\XTab\SupTab.dll =>PUP.SupTab
O2 - BHO: McAfee SiteAdvisor BHO [64Bits] - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} . (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
~ BHO: 3 Scanned in 00mn 00s



---\\ Barras do Internet Explorer (03))
O3 - Toolbar: McAfee SiteAdvisor Toolbar - [HKLM]{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} . (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
~ Toolbar: Scanned in 00mn 00s



---\\ Outras conexões do utilizador (04)
O4 - GS\QuickLaunch [IGOR]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O4 - GS\QuickLaunch [IGOR]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O4 - GS\QuickLaunch [IGOR]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\TaskBar [IGOR]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O4 - GS\TaskBar [IGOR]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe<a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O4 - GS\Program [IGOR]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe<a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O4 - GS\Desktop [IGOR]: Igor - Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
~ Global Startup: 7 Scanned in 00mn 09s



---\\ Aplicações iniciadas por registo & pastas (04)
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gerenciador de áudio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - HKCU\..\Run: [DelayShred] C:\Program Files (x86)\mcafee\mqs\ShrCL.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [mcpltui_exe] . (.McAfee, Inc. - McAfee Security Center.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Wow6432Node\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
O4 - HKUS\S-1-5-21-3395376235-1050388503-1019347766-1001\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - HKUS\S-1-5-21-3395376235-1050388503-1019347766-1001\..\Run: [DelayShred] C:\Program Files (x86)\mcafee\mqs\ShrCL.exe (.not file.)
~ Application: Scanned in 00mn 00s



---\\ Icones das opções IE invisiveis no painel das configurações (05)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Provedor de Correção de Nomeação de Emails.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Provedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
~ Winsock: 6 Scanned in 00mn 00s



---\\ Alteração Dominio/Clientes DNS (017)
O17 - HKLM\System\CCS\Services\Tcpip\..\{05C0A36E-615B-43DE-9C4A-AD02C5971774}: DhcpNameServer = 192.168.6.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{05DA15A7-34E1-4A23-BD8F-78465CB4F52F}: DhcpNameServer = 201.17.0.42 201.17.0.75 201.6.4.116
O17 - HKLM\System\CCS\Services\Tcpip\..\{05C0A36E-615B-43DE-9C4A-AD02C5971774}: DhcpDomain = fabrica.manaus
O17 - HKLM\System\CS1\Services\Tcpip\..\{05C0A36E-615B-43DE-9C4A-AD02C5971774}: DhcpNameServer = 192.168.6.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{05DA15A7-34E1-4A23-BD8F-78465CB4F52F}: DhcpNameServer = 201.17.0.42 201.17.0.75 201.6.4.116
O17 - HKLM\System\CS1\Services\Tcpip\..\{05C0A36E-615B-43DE-9C4A-AD02C5971774}: DhcpDomain = fabrica.manaus
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 201.17.0.42 201.17.0.75 201.6.4.116
~ Domain: Scanned in 00mn 00s



---\\ Protocolo adicional (018)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valor do Registo AppInit_DLLs e sub-chaves Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (...) -- igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Chave do Registo autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s



---\\ Lista dos serviços NT não Microsoft e não desativados (023)
O23 - Service: AVerRemote (AVerRemote) . (.AVerMedia - AVerRemote MFC Application.) - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService (AVerScheduleService) . (.No owner - ScheduleService Module.) - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: AVerUpdateServer (AVerUpdateServer) . (.AVerMedia TECHNOLOGIES, Inc. - AVer Update Service.) - C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Home Network (HomeNetSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: Tecnologia de armazenamento Intel(R) Rapid (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe
O23 - Service: IHProtect Service (IHProtect Service) . (.XTab system - ProtectSvc.exe.) - C:\Program Files (x86)\XTab\ProtectService.exe =>Adware.AgentODR
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation - Intel(R) ME Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc. - SiteAdvisor.) - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee AP Service (McAPExe) . (.McAfee, Inc. - McAfee Access Protection.) - C:\Program Files\McAfee\MSC\McAPexe.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Platform Services (mcpltsvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Anti-Malware Core (mfecore) . (.McAfee, Inc. - McAfee On-Access Scanner service.) - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) . (.McAfee, Inc. - McAfee Core Firewall Service.) - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc. - McAfee Process Validation Service.) - C:\Windows\system32\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
~ Services: 24 Scanned in 00mn 16s



---\\ Enumeração Ativa do Ambiente de trabalho & Editor MHTML (024)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Listagem dos dados do BootExecute (Bex) (034)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tarefas planificadas automaticamente (039)
[MD5.F172AD4E906D97ED8F071896FC6789DC] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912]
[MD5.F172AD4E906D97ED8F071896FC6789DC] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912]
[MD5.A9D30971B24700531BEB70C85D1B8328] [APT] [ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d] (.Intel Corporation.) -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [233792]
[MD5.A9D30971B24700531BEB70C85D1B8328] [APT] [ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon] (.Intel Corporation.) -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [233792]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1070]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1070]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1074]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1074]
O39 - APT: ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon - (.Intel Corporation.) -- C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job [868]
O39 - APT: ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon - (.Intel Corporation.) -- C:\Windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon [868]
O39 - APT: ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d - (.Intel Corporation.) -- C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job [870]
O39 - APT: ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d - (.Intel Corporation.) -- C:\Windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d [870]
~ Scheduled Task: 9 Scanned in 00mn 16s



---\\ Componentes instalados (ActiveSetup Installed Components) (040)
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Recursos do Windows Media Player.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API de tema do Windows.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extensão shell da pasta FTP do Microsoft Internet Explorer.) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Recursos do Windows Media Player.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitário de Inicialização por Usuário do Internet Explorer.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll
~ Active Setup: 9 Scanned in 00mn 02s



---\\ Drivers lançados ao arranque do sistema (041)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: C:\Windows\System32\drivers\ahcache.sys (ahcache) . (.Microsoft Corporation - Application Compatibility Cache.) - C:\Windows\System32\DRIVERS\ahcache.sys
O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys
O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys
O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Agendador de pacotes de serviço.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Driver do Subsistema de Buffer da Unidade R.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
O41 - Driver: C:\Windows\System32\drivers\vwififlt.sys (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys
~ Drivers: 32 Scanned in 00mn 01s



---\\ Software instalados (042)
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR
O42 - Logiciel: AviSynth 2.5 - (...) [HKLM][64Bits] -- AviSynth
O42 - Logiciel: CCE TV - (.CCE Technologies, Inc..) [HKLM][64Bits] -- InstallShield_{5016185F-05AF-455F-AA70-6B6E5D6D4E70}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: Fintek_CIR - (.Fintek_Inc.) [HKLM][64Bits] -- {7B732519-F534-4CD1-B0D3-FB2C70781444}
O42 - Logiciel: Galeria de Fotos - (.Microsoft Corporation.) [HKLM][64Bits] -- {9EE1AE8B-4872-41CA-8C9A-C33D899523E0}
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: Intel(R) Chipset Device Software - (.Intel Corporation.) [HKLM][64Bits] -- {B7CC660E-F31D-490C-BD2A-2CB2EC5A5E3A}
O42 - Logiciel: Intel(R) Manageability Engine Firmware Recovery Agent - (.Intel Corporation.) [HKLM][64Bits] -- {A6C48A9F-694A-4234-B3AA-62590B668927}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC}
O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573}
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77}
O42 - Logiciel: Malwarebytes Anti-Malware versão 2.0.4.1028 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: McAfee LiveSafe – Internet Security - (.McAfee, Inc..) [HKLM][64Bits] -- MSC
O42 - Logiciel: McAfee SiteAdvisor - (.McAfee, Inc..) [HKLM][64Bits] -- {35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}
O42 - Logiciel: REALTEK Wireless LAN Driver - (.REALTEK Semiconductor Corp..) [HKLM][64Bits] -- {9DAABC60-A5EF-41FF-B2B9-17329590CD5}
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Skype™ 7.1 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Software de dispositivo do Chipset Intel® - (.Intel(R) Corporation.) [HKLM][64Bits] -- {e48a2f61-851a-4155-82f9-af1b04db8c3b}
O42 - Logiciel: VLC media player 2.1.0 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WinRAR 5.20 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>P2P.BitTorrent
~ Logic: 33 Scanned in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\AVerMedia TECHNOLOGIES, Inc.]
[HKCU\Software\AppDataLow]
[HKCU\Software\BitTorrent] =>P2P.BitTorrent
[HKCU\Software\Chromium]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Disc Soft]
[HKCU\Software\GamesClient]
[HKCU\Software\GoldenGate]
[HKCU\Software\Google]
[HKCU\Software\IM Providers]
[HKCU\Software\Intel]
[HKCU\Software\Macromedia]
[HKCU\Software\McAfee]
[HKCU\Software\Mine]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Opera Software]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Skype]
[HKCU\Software\Trolltech]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Wow6432Node]
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\teras games]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\DTS]
[HKLM\Software\Dolby]
[HKLM\Software\Google]
[HKLM\Software\IM Providers]
[HKLM\Software\Intel]
[HKLM\Software\Khronos]
[HKLM\Software\Knowles]
[HKLM\Software\Macromedia]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfee]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\ODBC]
[HKLM\Software\Policies]
[HKLM\Software\RTLSetup]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\SiteAdvisor]
[HKLM\Software\SonicFocus]
[HKLM\Software\VideoLAN]
[HKLM\Software\Waves Audio]
[HKLM\Software\Wow6432Node\AVerMedia TECHNOLOGIES, Inc.]
[HKLM\Software\Wow6432Node\AVerUpdate]
[HKLM\Software\Wow6432Node\Adobe]
[HKLM\Software\Wow6432Node\AdwCleaner]
[HKLM\Software\Wow6432Node\AppDataLow]
[HKLM\Software\Wow6432Node\Classes]
[HKLM\Software\Wow6432Node\Clients]
[HKLM\Software\Wow6432Node\Disc Soft]
[HKLM\Software\Wow6432Node\Fintek_Inc]
[HKLM\Software\Wow6432Node\Google]
[HKLM\Software\Wow6432Node\IHProtect] =>Adware.AgentODR
[HKLM\Software\Wow6432Node\IM Providers]
[HKLM\Software\Wow6432Node\InstallShield]
[HKLM\Software\Wow6432Node\Intel]
[HKLM\Software\Wow6432Node\Khronos]
[HKLM\Software\Wow6432Node\Macromedia]
[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]
[HKLM\Software\Wow6432Node\McAfee.com]
[HKLM\Software\Wow6432Node\McAfee]
[HKLM\Software\Wow6432Node\MozillaPlugins]
[HKLM\Software\Wow6432Node\Mozilla]
[HKLM\Software\Wow6432Node\Nuance]
[HKLM\Software\Wow6432Node\ODBC]
[HKLM\Software\Wow6432Node\Opera Software]
[HKLM\Software\Wow6432Node\Policies]
[HKLM\Software\Wow6432Node\REALTEK Semiconductor Corp.]
[HKLM\Software\Wow6432Node\Realtek]
[HKLM\Software\Wow6432Node\RegisteredApplications]
[HKLM\Software\Wow6432Node\RtWLan]
[HKLM\Software\Wow6432Node\SiteAdvisor]
[HKLM\Software\Wow6432Node\Skype]
[HKLM\Software\Wow6432Node\SupDp] =>PUP.SupTab
[HKLM\Software\Wow6432Node\WinRAR]
[HKLM\Software\Wow6432Node\omiga-plusSoftware] =>Hijacker.OmigaPlus
[HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab
[HKLM\Software\Wow6432Node\supWindowsMangerProtect] =>PUP.Fuyu
[HKLM\Software\Wow6432Node]
~ Key Software: 152 Scanned in 00mn 00s



---\\ Conteúdo das pastas Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 22/05/2014 - 18:42:43 - [] ----D C:\Program Files (x86)\Adobe
O43 - CFD: 26/01/2015 - 17:29:21 - [] ----D C:\Program Files (x86)\AVerMedia
O43 - CFD: 22/05/2014 - 18:42:46 - [] ----D C:\Program Files (x86)\AviSynth 2.5
O43 - CFD: 24/06/2014 - 18:51:00 - [] ----D C:\Program Files (x86)\Cisco
O43 - CFD: 29/01/2015 - 20:21:52 - [] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 26/01/2015 - 13:54:17 - [] ----D C:\Program Files (x86)\Google
O43 - CFD: 24/06/2014 - 18:59:18 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 21/08/2014 - 09:49:08 - [] ----D C:\Program Files (x86)\Intel
O43 - CFD: 28/01/2015 - 18:35:16 - [] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 23/05/2014 - 10:17:10 - [] ----D C:\Program Files (x86)\lenovowinwinbr
O43 - CFD: 28/01/2015 - 00:44:05 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware
O43 - CFD: 02/02/2015 - 23:17:51 - [] ----D C:\Program Files (x86)\McAfee
O43 - CFD: 23/05/2014 - 10:20:46 - [] ----D C:\Program Files (x86)\mcafee.com
O43 - CFD: 22/05/2014 - 18:38:12 - [] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 22/05/2014 - 18:36:51 - [] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 22/08/2013 - 13:36:30 - [] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 22/05/2014 - 18:01:39 - [] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 26/01/2015 - 16:58:49 - [] ----D C:\Program Files (x86)\Opera
O43 - CFD: 26/01/2015 - 16:59:32 - [] ----D C:\Program Files (x86)\OperaHelper
O43 - CFD: 26/01/2015 - 19:03:00 - [0] ----D C:\Program Files (x86)\RBM
O43 - CFD: 24/06/2014 - 18:43:28 - [] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 24/06/2014 - 18:51:00 - [] ----D C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver
O43 - CFD: 22/05/2014 - 18:01:39 - [] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 29/01/2015 - 20:21:52 - [] R---D C:\Program Files (x86)\Skype
O43 - CFD: 26/01/2015 - 20:29:31 - [] ----D C:\Program Files (x86)\Steam
O43 - CFD: 29/01/2015 - 17:10:25 - [] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 22/05/2014 - 18:36:49 - [] ----D C:\Program Files (x86)\Windows Live
O43 - CFD: 18/03/2014 - 07:30:27 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - 08:23:21 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - 08:23:21 - [] ----D C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 22/08/2013 - 13:36:30 - [] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 18/03/2014 - 07:30:27 - [] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 18/03/2014 - 08:23:21 - [] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 22/08/2013 - 13:36:30 - [] -SH-D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 22/08/2013 - 13:36:30 - [] ----D C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 26/01/2015 - 20:07:02 - [] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 05/02/2015 - 00:26:52 - [] ----D C:\Program Files (x86)\XTab
O43 - CFD: 05/02/2015 - 01:33:05 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 22/05/2014 - 18:42:43 - [] ----D C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 24/06/2014 - 18:58:18 - [] ----D C:\Program Files (x86)\Common Files\AVerMedia
O43 - CFD: 26/01/2015 - 13:52:07 - [] ----D C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 24/06/2014 - 19:03:00 - [] ----D C:\Program Files (x86)\Common Files\Intel Corporation
O43 - CFD: 23/05/2014 - 10:21:38 - [] ----D C:\Program Files (x86)\Common Files\mcafee
O43 - CFD: 29/01/2015 - 17:10:01 - [] ----D C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 24/06/2014 - 18:39:20 - [] ----D C:\Program Files (x86)\Common Files\postureAgent
O43 - CFD: 22/08/2013 - 13:36:33 - [] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 29/01/2015 - 20:21:52 - [] ----D C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 18/03/2014 - 07:30:27 - [] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 22/05/2014 - 18:35:54 - [] ----D C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 22/05/2014 - 18:42:43 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 22/08/2013 - 12:45:52 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 26/01/2015 - 18:05:44 - [] ----D C:\ProgramData\AVerTV 3D
O43 - CFD: 13/10/2014 - 15:38:45 - [] -SH-D C:\ProgramData\Dados de Aplicativos
O43 - CFD: 26/01/2015 - 18:39:00 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 22/08/2013 - 12:45:52 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 13/10/2014 - 15:38:45 - [] -SH-D C:\ProgramData\Documentos
O43 - CFD: 22/08/2013 - 12:45:52 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 05/02/2015 - 00:26:33 - [] ----D C:\ProgramData\IHProtectUpDate =>Adware.AgentODR
O43 - CFD: 24/06/2014 - 18:50:03 - [] ----D C:\ProgramData\Intel
O43 - CFD: 28/01/2015 - 01:04:41 - [] ----D C:\ProgramData\kHSwUWh
O43 - CFD: 28/01/2015 - 00:43:57 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 26/01/2015 - 19:30:08 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 13/10/2014 - 15:38:45 - [] -SH-D C:\ProgramData\Menu Iniciar
O43 - CFD: 26/01/2015 - 13:43:54 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 22/05/2014 - 18:36:00 - [] ----D C:\ProgramData\Microsoft OneDrive
O43 - CFD: 13/10/2014 - 15:38:45 - [] -SH-D C:\ProgramData\Modelos
O43 - CFD: 24/06/2014 - 18:55:58 - [] ----D C:\ProgramData\Package Cache
O43 - CFD: 22/05/2014 - 18:38:19 - [] ----D C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 29/01/2015 - 20:21:56 - [] ----D C:\ProgramData\Skype
O43 - CFD: 22/08/2013 - 12:45:52 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 22/08/2013 - 12:45:52 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 05/02/2015 - 00:25:50 - [] ----D C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu
O43 - CFD: 22/08/2013 - 13:36:33 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 18/03/2014 - 07:33:10 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 18/03/2014 - 08:23:26 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 24/06/2014 - 18:58:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCE
O43 - CFD: 26/01/2015 - 13:54:27 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 21/08/2014 - 09:49:13 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
O43 - CFD: 22/08/2013 - 13:36:33 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 28/01/2015 - 00:44:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 05/02/2015 - 01:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
O43 - CFD: 29/01/2015 - 20:21:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 24/06/2014 - 18:58:51 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 18/03/2014 - 08:23:26 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 18/03/2014 - 07:33:10 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 26/01/2015 - 20:07:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 05/02/2015 - 01:33:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
O43 - CFD: 26/01/2015 - 13:40:26 - [] ----D C:\Users\IGOR\AppData\Roaming\Adobe
O43 - CFD: 26/01/2015 - 20:02:31 - [0] ----D C:\Users\IGOR\AppData\Roaming\BitTorrent =>P2P.BitTorrent
O43 - CFD: 26/01/2015 - 18:39:59 - [0] ----D C:\Users\IGOR\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 26/01/2015 - 18:32:23 - [] --H-D C:\Users\IGOR\AppData\Roaming\GoldenGate
O43 - CFD: 26/01/2015 - 13:43:02 - [] ----D C:\Users\IGOR\AppData\Roaming\Intel Corporation
O43 - CFD: 22/05/2014 - 18:42:43 - [] ----D C:\Users\IGOR\AppData\Roaming\Macromedia
O43 - CFD: 29/01/2015 - 12:49:58 - [] -S--D C:\Users\IGOR\AppData\Roaming\Microsoft
O43 - CFD: 26/01/2015 - 16:57:05 - [] ----D C:\Users\IGOR\AppData\Roaming\Opera Software
O43 - CFD: 29/01/2015 - 23:29:04 - [] ----D C:\Users\IGOR\AppData\Roaming\Skype
O43 - CFD: 05/02/2015 - 01:34:59 - [] ----D C:\Users\IGOR\AppData\Roaming\uTorrent =>P2P.µTorrent
O43 - CFD: 26/01/2015 - 20:07:13 - [] ----D C:\Users\IGOR\AppData\Roaming\WinRAR
O43 - CFD: 05/02/2015 - 01:34:57 - [] ----D C:\Users\IGOR\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 26/01/2015 - 13:52:13 - [] ----D C:\Users\IGOR\AppData\Local\Apps
O43 - CFD: 26/01/2015 - 13:40:19 - [] ----D C:\Users\IGOR\AppData\Local\AVerMedia
O43 - CFD: 04/02/2015 - 16:13:18 - [] ----D C:\Users\IGOR\AppData\Local\CrashDumps
O43 - CFD: 26/01/2015 - 13:39:55 - [] -SH-D C:\Users\IGOR\AppData\Local\Dados de Aplicativos
O43 - CFD: 26/01/2015 - 13:53:01 - [0] ----D C:\Users\IGOR\AppData\Local\Deployment
O43 - CFD: 27/01/2015 - 23:13:24 - [] ----D C:\Users\IGOR\AppData\Local\Diagnostics
O43 - CFD: 29/01/2015 - 16:43:50 - [] ----D C:\Users\IGOR\AppData\Local\ElevatedDiagnostics
O43 - CFD: 01/02/2015 - 00:49:01 - [] -SH-D C:\Users\IGOR\AppData\Local\EmieBrowserModeList
O43 - CFD: 26/01/2015 - 16:42:24 - [] -SH-D C:\Users\IGOR\AppData\Local\EmieSiteList
O43 - CFD: 26/01/2015 - 16:42:24 - [] -SH-D C:\Users\IGOR\AppData\Local\EmieUserList
O43 - CFD: 26/01/2015 - 13:54:32 - [] ----D C:\Users\IGOR\AppData\Local\Google
O43 - CFD: 26/01/2015 - 13:39:55 - [] -SH-D C:\Users\IGOR\AppData\Local\Histórico
O43 - CFD: 27/01/2015 - 23:13:22 - [] ----D C:\Users\IGOR\AppData\Local\Microsoft
O43 - CFD: 26/01/2015 - 16:57:09 - [] ----D C:\Users\IGOR\AppData\Local\Opera Software
O43 - CFD: 26/01/2015 - 19:48:59 - [] ----D C:\Users\IGOR\AppData\Local\Packages
O43 - CFD: 26/01/2015 - 16:20:28 - [] ----D C:\Users\IGOR\AppData\Local\Programs
O43 - CFD: 26/01/2015 - 13:57:05 - [] ----D C:\Users\IGOR\AppData\Local\Skype
O43 - CFD: 26/01/2015 - 20:29:32 - [] ----D C:\Users\IGOR\AppData\Local\Sports Interactive
O43 - CFD: 05/02/2015 - 01:34:24 - [] ----D C:\Users\IGOR\AppData\Local\Temp
O43 - CFD: 26/01/2015 - 13:39:55 - [] -SH-D C:\Users\IGOR\AppData\Local\Temporary Internet Files
O43 - CFD: 27/01/2015 - 18:19:18 - [] ----D C:\Users\IGOR\AppData\Local\VirtualStore
O43 - CFD: 18/03/2014 - 08:23:26 - [] R---D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 22/08/2013 - 13:36:32 - [] R---D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 28/01/2015 - 18:40:13 - [] R---D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 22/08/2013 - 13:36:32 - [] ----D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 28/01/2015 - 18:40:13 - [] R---D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 23/05/2014 - 12:17:31 - [] R---D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 26/01/2015 - 20:07:02 - [] ----D C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
~ Program Folder: 127 Scanned in 00mn 02s



---\\ Últimos ficheiros alterados ou criados no Windows e Sistema32 (044)
O44 - LFC:[MD5.E24D9F01C49EAEF30EC5147873742A3C] - 02/02/2015 - 22:17:40 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [338136]
O44 - LFC:[MD5.8C8F0FCB260A99B4DF96D1F942548330] - 02/02/2015 - 22:24:52 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1800588]
O44 - LFC:[MD5.B1475FA4947D95C25934D536EA1348D6] - 02/02/2015 - 22:24:52 ---A- . (...) -- C:\Windows\System32\perfc009.dat [135930]
O44 - LFC:[MD5.AE34BC21D7602AF5C8E659060A0117E1] - 02/02/2015 - 22:24:52 ---A- . (...) -- C:\Windows\System32\perfh009.dat [723316]
O44 - LFC:[MD5.29DB9CE141B5AA22D90101D986AD8961] - 02/02/2015 - 22:24:52 ---A- . (...) -- C:\Windows\System32\prfc0416.dat [158832]
O44 - LFC:[MD5.FFDE50D1B0864F7D93F995BEDAB4E309] - 02/02/2015 - 22:24:52 ---A- . (...) -- C:\Windows\System32\prfh0416.dat [775740]
O44 - LFC:[MD5.15E2DD9B0A173AAF965D2E585B6EA3B5] - 04/02/2015 - 23:32:14 ---A- . (...) -- C:\Windows\PFRO.log [98214]
O44 - LFC:[MD5.FC273E6B811F678EA5518A27D57E0879] - 04/02/2015 - 23:42:26 ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [298120]
O44 - LFC:[MD5.6E96D4FD9CE37F07FD9CE2FB564B74F8] - 05/02/2015 - 00:18:23 ---A- . (...) -- C:\Windows\setupact.log [2091]
O44 - LFC:[MD5.829F6B3086CEF2899B7C97EA29BAB0FC] - 05/02/2015 - 00:20:18 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.A9B9EE1B29ACE23379E226685DBAFA02] - 05/02/2015 - 00:30:18 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1150361]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26/01/2015 - 15:57:30 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.9F45771914360A925252A1B7226EC7EC] - 26/01/2015 - 16:06:37 ---A- . (...) -- C:\Windows\System32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat [451]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26/01/2015 - 17:12:30 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf [0]
O44 - LFC:[MD5.1523026E76823F5D903C814250747995] - 26/01/2015 - 18:22:26 ---A- . (...) -- C:\Windows\win.ini [226]
O44 - LFC:[MD5.29F981739E50305128022CBE10B3659C] - 26/01/2015 - 18:36:22 ---A- . (.McAfee, Inc. - McAfee HIP IPS Driver.) -- C:\Windows\System32\Drivers\HipShieldK.sys [197704]
O44 - LFC:[MD5.CB136B267569A62EF63D798BC90ABD5A] - 27/01/2015 - 10:34:23 ---A- . (...) -- C:\Windows\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat [144]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 27/01/2015 - 23:26:46 ---A- . (...) -- C:\essai.txt [0]
O44 - LFC:[MD5.CA43F8904E24BBE49982E4C0B29E6579] - 27/01/2015 - 23:43:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [25816]
O44 - LFC:[MD5.478CC94C937D235CB0A96AB8F2359D81] - 27/01/2015 - 23:43:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [93400]
O44 - LFC:[MD5.9D7BFFDB5FA62B600DF1FCB4919D9D79] - 27/01/2015 - 23:43:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [64216]
O44 - LFC:[MD5.CCC6D7250D01DA7E5499B0722CF6CAE3] - 28/01/2015 - 11:03:05 ---A- . (.Microsoft Corporation - TWINUI.APPCORE.) -- C:\Windows\System32\twinui.appcore.dll [1054208]
O44 - LFC:[MD5.9FA466A42109F408AC6C2848E851C38A] - 28/01/2015 - 11:03:05 ---A- . (.Microsoft Corporation - twinapi.appcore.) -- C:\Windows\System32\twinapi.appcore.dll [555736]
O44 - LFC:[MD5.F381B380B7B2704EA4C0F8D8C49C1C50] - 28/01/2015 - 11:40:15 ---A- . (.Microsoft Corporation - MDMAgent.) -- C:\Windows\System32\MDMAgent.exe [623616]
O44 - LFC:[MD5.E4A75F7BA48F4281405C782E3DB9F828] - 28/01/2015 - 11:40:19 ---A- . (.Microsoft Corporation - Executor de Fila de Operações Primitivas.) -- C:\Windows\System32\poqexec.exe [146432]
O44 - LFC:[MD5.A770340FC02B999EF0DE6C2A6BC8437C] - 28/01/2015 - 11:40:27 ---A- . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\Windows\System32\Drivers\intelpep.sys [39744]
O44 - LFC:[MD5.24A8DFC07E4BAF29AEA26E383D4CC886] - 28/01/2015 - 11:40:27 ---A- . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\Windows\System32\Drivers\pdc.sys [86336]
O44 - LFC:[MD5.B02118A776C368F7EE1A8CC81378D265] - 28/01/2015 - 11:40:27 ---A- . (.Microsoft Corporation - SD Crashdump Port Driver.) -- C:\Windows\System32\Drivers\dumpsd.sys [153920]
O44 - LFC:[MD5.7B7C482CF48E6EE33664340D1A78E6FE] - 28/01/2015 - 11:40:27 ---A- . (.Microsoft Corporation - SecureDigital Bus Driver.) -- C:\Windows\System32\Drivers\sdbus.sys [238912]
O44 - LFC:[MD5.DB7815ACB2D8F7CB03807059969F13B6] - 28/01/2015 - 11:40:34 ---A- . (.Microsoft Corporation - Microsoft Windows MRM.) -- C:\Windows\System32\MrmCoreR.dll [1091072]
O44 - LFC:[MD5.182561A14F2E93E81E66FE3700D17A5A] - 28/01/2015 - 11:40:41 ---A- . (.Microsoft Corporation - Family Safety Filter Driver.) -- C:\Windows\System32\Drivers\wpcfltr.sys [55328]
O44 - LFC:[MD5.52E94AE3C9FF1E18A1EA125C4FFB0EEC] - 28/01/2015 - 11:40:41 ---A- . (.Microsoft Corporation - Painel de Controle dos Controles dos Pais.) -- C:\Windows\System32\wpccpl.dll [2834944]
O44 - LFC:[MD5.D1E3B8D9130C70F6A3D4FDB52373FF34] - 28/01/2015 - 11:40:45 ---A- . (.Microsoft Corporation - WER Diagnostic Controller.) -- C:\Windows\System32\werdiagcontroller.dll [37888]
O44 - LFC:[MD5.A41B72F81B389786805CC4D5767B5FBC] - 28/01/2015 - 11:40:46 ---A- . (.Microsoft Corporation - Code Integrity Module (Test).) -- C:\Windows\System32\ci.dll [531616]
O44 - LFC:[MD5.2C354FA91EF605007FD11BB89EED2266] - 28/01/2015 - 11:40:46 ---A- . (.Microsoft Corporation - DLL do Relatório de Falha do Modo de Usuári.) -- C:\Windows\System32\Faultrep.dll [413248]
O44 - LFC:[MD5.41C501FD9D42F3F04A8532C73E09F356] - 28/01/2015 - 11:40:46 ---A- . (.Microsoft Corporation - Media Foundation Crash Dump Encryption DLL.) -- C:\Windows\System32\EncDump.dll [108944]
O44 - LFC:[MD5.9404704666256045F5BA9B290953B4D0] - 28/01/2015 - 11:40:46 ---A- . (.Microsoft Corporation - Relatório de Falhas do Windows.) -- C:\Windows\System32\WerFaultSecure.exe [38264]
O44 - LFC:[MD5.6DCD12586353DC6307AC781045CA13A4] - 28/01/2015 - 11:40:46 ---A- . (.Microsoft Corporation - Relatório de Problemas do Windows.) -- C:\Windows\System32\WerFault.exe [465320]
O44 - LFC:[MD5.0BCDEB035B9346D3C3C6C8BB1AA7F38C] - 28/01/2015 - 11:40:46 ---A- . (.Microsoft Corporation - Windows Problem Reporting.) -- C:\Windows\System32\wermgr.exe [139984]
O44 - LFC:[MD5.6F237EE5DDA34EAF3D9C79D4A283E250] - 28/01/2015 - 11:40:48 ---A- . (.Microsoft Corporation - Audio Engine.) -- C:\Windows\System32\AudioEng.dll [482872]
O44 - LFC:[MD5.E24D3259769A0218FE19BB306821C2E5] - 28/01/2015 - 11:40:48 ---A- . (.Microsoft Corporation - Audio Ks Endpoint.) -- C:\Windows\System32\AUDIOKSE.dll [394120]
O44 - LFC:[MD5.8779FDAE68BC948B0FE152E758CC8DA7] - 28/01/2015 - 11:40:48 ---A- . (.Microsoft Corporation - Construtor de Pontos de Extremidade de Áudi.) -- C:\Windows\System32\AudioEndpointBuilder.dll [229888]
O44 - LFC:[MD5.8EBC741DDE9409038262E2F317ED7CCE] - 28/01/2015 - 11:40:48 ---A- . (.Microsoft Corporation - DLL do Relatório de Erros do Windows.) -- C:\Windows\System32\wer.dll [535640]
O44 - LFC:[MD5.770BAA636F3B61DA7E414421444F84FD] - 28/01/2015 - 11:40:48 ---A- . (.Microsoft Corporation - Isolamento de Gráfico de Dispositivo de Áud.) -- C:\Windows\System32\audiodg.exe [272248]
O44 - LFC:[MD5.428F083690D7AAA012338FD5A0663EE3] - 28/01/2015 - 11:40:48 ---A- . (.Microsoft Corporation - Sessão de Áudio.) -- C:\Windows\System32\AudioSes.dll [500016]
O44 - LFC:[MD5.61EA45A645854FE81D8A924E2D93DFFE] - 28/01/2015 - 11:40:49 ---A- . (.Microsoft Corporation - Serviço de Áudio do Windows.) -- C:\Windows\System32\audiosrv.dll [911360]
O44 - LFC:[MD5.78FC2B2BA0E5E1C9249E3157D4EE9BC7] - 28/01/2015 - 11:40:50 ---A- . (.Microsoft Corporation - Edição com o DirectShow..) -- C:\Windows\System32\qedit.dll [586240]
O44 - LFC:[MD5.FE11972797DED38CA55E88BD3579F6A2] - 28/01/2015 - 11:40:53 ---A- . (.Microsoft Corporation - Indicador de Status da Conectividade de Red.) -- C:\Windows\System32\ncsi.dll [360448]
O44 - LFC:[MD5.6319232C1CE39AC35316CF51910EEEB5] - 28/01/2015 - 11:40:53 ---A- . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\System32\nlaapi.dll [86016]
O44 - LFC:[MD5.E94EB2A95D7D016E119C4D6868788831] - 28/01/2015 - 11:40:53 ---A- . (.Microsoft Corporation - Reconhecimento de Locais de Rede 2.) -- C:\Windows\System32\nlasvc.dll [391680]
O44 - LFC:[MD5.48BA326A3DBA5B5BEB5F2777F4618696] - 28/01/2015 - 11:41:11 ---A- . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\Drivers\usbehci.sys [89944]
O44 - LFC:[MD5.08DCA300264238F9AE941302321F3D54] - 28/01/2015 - 11:41:11 ---A- . (.Microsoft Corporation - Hardware Abstraction Layer DLL.) -- C:\Windows\System32\hal.dll [423768]
O44 - LFC:[MD5.42D257559F97B30A94A027EB4555C62F] - 28/01/2015 - 11:41:11 ---A- . (.Microsoft Corporation - Provedor de Credenciais de Senha de Uso Úni.) -- C:\Windows\System32\DaOtpCredentialProvider.dll [323584]
O44 - LFC:[MD5.064260B3A5868AC894A4943543BC7AB7] - 28/01/2015 - 11:41:11 ---A- . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbuhci.sys [37376]
O44 - LFC:[MD5.D79920BE4E6683D3AB50F71457A4F6C6] - 28/01/2015 - 11:41:11 ---A- . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\Drivers\usbd.sys [27480]
O44 - LFC:[MD5.FE0ADF5028EB8C1339B66B3AEDE3FEF9] - 28/01/2015 - 11:41:12 ---A- . (.Microsoft Corporation - Driver de Porta USB 1.1 e 2.0.) -- C:\Windows\System32\Drivers\usbport.sys [440664]
O44 - LFC:[MD5.1A54E3DF2CBB8DBE8A17C87BB07E3A7E] - 28/01/2015 - 11:41:12 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Biblioteca de P.) -- C:\Windows\System32\WUDFPlatform.dll [209408]
O44 - LFC:[MD5.B312E157D20E727F30EAB3A250441B6F] - 28/01/2015 - 11:41:12 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Processo de Hos.) -- C:\Windows\System32\WUDFHost.exe [284672]
O44 - LFC:[MD5.9CDC2059A23E3C9B57696178508777E7] - 28/01/2015 - 11:41:12 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Serviço de Estr.) -- C:\Windows\System32\WUDFSvc.dll [99840]
O44 - LFC:[MD5.D537815E450A149752C15868392AD1F3] - 28/01/2015 - 11:41:12 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFPf.sys [110592]
O44 - LFC:[MD5.7CCBBCEE408A5DBE3FE47297DB5A6CFC] - 28/01/2015 - 11:41:12 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFRd.sys [227840]
O44 - LFC:[MD5.418B5117F187DFFD96C52325CA0DF153] - 28/01/2015 - 11:41:23 ---A- . (.Microsoft Corporation - Microsoft Windows Codecs Library.) -- C:\Windows\System32\WindowsCodecs.dll [1762840]
O44 - LFC:[MD5.A3871DED5ED88F59C0D1396761708F81] - 28/01/2015 - 11:41:49 ---A- . (.Microsoft Corporation - Host de Aplicativo HTML da Microsoft(R).) -- C:\Windows\System32\mshta.exe [13824]
O44 - LFC:[MD5.E99E2E88BFE584184AE92B1F8995CE93] - 28/01/2015 - 11:41:49 ---A- . (.Microsoft Corporation - Mapa de versão IOD.) -- C:\Windows\System32\iesetup.dll [66560]
O44 - LFC:[MD5.66585D645C4E23A0FD5124BD714AE020] - 28/01/2015 - 11:41:49 ---A- . (.Microsoft Corporation - Microsoft Feeds Synchronization.) -- C:\Windows\System32\msfeedssync.exe [12800]
O44 - LFC:[MD5.CDC8A85EB301A8CBE55A81A1D55AF5E5] - 28/01/2015 - 11:41:50 ---A- . (.Microsoft Corporation - ADVPACK.) -- C:\Windows\System32\IEAdvpack.dll [132096]
O44 - LFC:[MD5.4B9C652BD0FD95A9E6123913C35519D6] - 28/01/2015 - 11:41:50 ---A- . (.Microsoft Corporation - Autoextrator de arquivo de gabinete Win32.) -- C:\Windows\System32\wextract.exe [143872]
O44 - LFC:[MD5.A7F53772ECAE2F44B455D14F71179940] - 28/01/2015 - 11:41:50 ---A- . (.Microsoft Corporation - IE ETW Collector Proxy Stub Resources.) -- C:\Windows\System32\ieetwproxystub.dll [48640]
O44 - LFC:[MD5.6A7F8D139610E5F3F158182778EF9275] - 28/01/2015 - 11:41:50 ---A- . (.Microsoft Corporation - Processamento de RunOnce estendido com inte.) -- C:\Windows\System32\iernonce.dll [34304]
O44 - LFC:[MD5.CA2F3153EF3BCB0BD3A8984C933DF604] - 28/01/2015 - 11:41:50 ---A- . (.Microsoft Corporation - Wizard.) -- C:\Windows\System32\iexpress.exe [167424]
O44 - LFC:[MD5.3721721151DB49457B0FD35E0C04594C] - 28/01/2015 - 11:41:51 ---A- . (.Microsoft Corporation - Classificação da Internet e DLL de gerencia.) -- C:\Windows\System32\msrating.dll [199680]
O44 - LFC:[MD5.D66D11191B48007179B0A77DC0717267] - 28/01/2015 - 11:41:51 ---A- . (.Microsoft Corporation - DLL do Gerenciador de Licenças da Microsoft.) -- C:\Windows\System32\licmgr10.dll [33280]
O44 - LFC:[MD5.6096209CB47D61499C3608B9C25B073C] - 28/01/2015 - 11:41:51 ---A- . (.Microsoft Corporation - IE PNG plugin image decoder.) -- C:\Windows\System32\pngfilt.dll [64512]
O44 - LFC:[MD5.161BC2E883A8D8759A4DCF2A85AF9128] - 28/01/2015 - 11:41:51 ---A- . (.Microsoft Corporation - IE plugin image decoder support DLL.) -- C:\Windows\System32\imgutil.dll [51200]
O44 - LFC:[MD5.F54E1190251EB245183BF16D6C315613] - 28/01/2015 - 11:41:51 ---A- . (.Microsoft Corporation - Internet Shortcut Shell Extension DLL.) -- C:\Windows\System32\url.dll [237568]
O44 - LFC:[MD5.DD8FD33C108F14681A410067AB21DDF3] - 28/01/2015 - 11:41:51 ---A- . (.Microsoft Corporation - Visualizador de controles de objetos.) -- C:\Windows\System32\occache.dll [152064]
O44 - LFC:[MD5.284070B045F8B11B4A1FB32F72023038] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - Conversor de HTML da Microsoft.) -- C:\Windows\System32\html.iec [417280]
O44 - LFC:[MD5.17A157A4225CF562202AC71DB8103177] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - DAC for Trident DOM.) -- C:\Windows\System32\MshtmlDac.dll [88064]
O44 - LFC:[MD5.8AE1AC97407CD82D8389390C21430579] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - IE Sysprep Provider.) -- C:\Windows\System32\iesysprep.dll [111616]
O44 - LFC:[MD5.F79E5258AF040A8AD83C7C1273A071C3] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [54784]
O44 - LFC:[MD5.A348DEFC16B6FBC88B7D61C3B861BCB1] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - Mecanismo de instalação.) -- C:\Windows\System32\inseng.dll [107520]
O44 - LFC:[MD5.85E97591864F3125C5B08FB44E0E8078] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - Sincronização em Segundo Plano para Feeds M.) -- C:\Windows\System32\msfeedsbs.dll [60416]
O44 - LFC:[MD5.00FB2FB8C27C834CF575BC415B80F995] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - TDC ActiveX Control.) -- C:\Windows\System32\tdc.ocx [87552]
O44 - LFC:[MD5.1C3C54FA2D620DF3093F356A56EC5957] - 28/01/2015 - 11:41:52 ---A- . (.Microsoft Corporation - Utilitário de Instalação Autônoma do IE 7.0.) -- C:\Windows\System32\ieUnatt.exe [144384]
O44 - LFC:[MD5.F0A53129AE95A895EC8C4DC36E1797A2] - 28/01/2015 - 11:41:53 ---A- . (.Microsoft Corporation - Componente do Microsoft Office 2000.) -- C:\Windows\System32\hlink.dll [108544]
O44 - LFC:[MD5.E40D3696BE4852956669C285038B37A6] - 28/01/2015 - 11:41:53 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [114688]
O44 - LFC:[MD5.62CFEE2A516C68540486EBF26F18ED4C] - 28/01/2015 - 11:41:53 ---A- . (.Microsoft Corporation - Objetos pares do Internet Explorer.) -- C:\Windows\System32\iepeers.dll [145408]
O44 - LFC:[MD5.D248949FCF2B72C1FD4EC15DA92065C0] - 28/01/2015 - 11:41:54 ---A- . (.Microsoft Corporation - Monitor de Sites.) -- C:\Windows\System32\webcheck.dll [262144]
O44 - LFC:[MD5.587DEBB59F5F14C9610966FB14A33607] - 28/01/2015 - 11:41:57 ---A- . (.Microsoft Corporation - Mecanismo da Interface do Usuário do Intern.) -- C:\Windows\System32\ieui.dll [633856]
O44 - LFC:[MD5.DE58DE2C6C8439B7174D6D3568AA4A80] - 28/01/2015 - 11:41:58 ---A- . (.Microsoft Corporation - Microsoft ® JScript Diagnostics.) -- C:\Windows\System32\jscript9diag.dll [814080]
O44 - LFC:[MD5.A41AC7E8D142FD0ECF6EF7F1BB63D478] - 28/01/2015 - 11:41:58 ---A- . (.Microsoft Corporation - Microsoft ® JScript.) -- C:\Windows\System32\jscript.dll [812544]
O44 - LFC:[MD5.507DC5EE1363EEB7D986B1026DF4E39D] - 28/01/2015 - 11:41:59 ---A- . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [1032704]
O44 - LFC:[MD5.1D294810D3A8A8F722E86AA001F54DCC] - 28/01/2015 - 11:41:59 ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [580096]
O44 - LFC:[MD5.D478A4CF07FB8ADF72FB16B88E8030B8] - 28/01/2015 - 11:42:03 ---A- . (.Microsoft Corporation - Visualizador de HTML da Microsoft (R).) -- C:\Windows\System32\mshtml.dll [25059840]
O44 - LFC:[MD5.4AF089160FE082E5EA5C4AA72782DCA2] - 28/01/2015 - 11:42:04 ---A- . (.Microsoft Corporation - Internet Extensions para Win32.) -- C:\Windows\System32\wininet.dll [2358272]
O44 - LFC:[MD5.EFBA893429814EA3244C87C2D1256618] - 28/01/2015 - 11:42:04 ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter.) -- C:\Windows\System32\ieapfltr.dll [800768]
O44 - LFC:[MD5.8D64466AD12CA5677CD0099C43C58569] - 28/01/2015 - 11:42:05 ---A- . (.Microsoft Corporation - Microsoft ® JScript.) -- C:\Windows\System32\jscript9.dll [6039552]
O44 - LFC:[MD5.DB10D681314714E0D4623E4C0CF6654A] - 28/01/2015 - 11:42:05 ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [92160]
O44 - LFC:[MD5.556D271F4243B273EDA353512BF3608A] - 28/01/2015 - 11:42:06 ---A- . (.Microsoft Corporation - Navegador da Internet.) -- C:\Windows\System32\ieframe.dll [14412800]
O44 - LFC:[MD5.982B871A25B5078093FAD82D0AB0E3FC] - 28/01/2015 - 11:42:07 ---A- . (.Microsoft Corporation - Executar utilitário de tempo do Internet Ex.) -- C:\Windows\System32\iertutil.dll [2885120]
O44 - LFC:[MD5.3FE71E2A5BD3EC652E64FC8BCEFEDD2C] - 28/01/2015 - 11:42:08 ---A- . (.Microsoft Corporation - Painel de Controle da Internet.) -- C:\Windows\System32\inetcpl.cpl [2125312]
O44 - LFC:[MD5.14BA910E7731FC84EB85328BD0F1EE81] - 28/01/2015 - 11:42:09 ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [800768]
O44 - LFC:[MD5.E7A2061ADF0F4D430FECDA1E8D6B7BA6] - 28/01/2015 - 11:42:11 ---A- . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\Windows\System32\urlmon.dll [1548288]
O44 - LFC:[MD5.DDE455CF1B9F43775A53A4E577DFDC54] - 28/01/2015 - 11:42:11 ---A- . (.Microsoft Corporation - Identidade visual IEAK.) -- C:\Windows\System32\iedkcs32.dll [373760]
O44 - LFC:[MD5.C9AB2198141844D3DF96B4552CE9D5AB] - 28/01/2015 - 11:42:13 ---A- . (.Microsoft Corporation - JavaScript Performance Collection Agent.) -- C:\Windows\System32\JavaScriptCollectionAgent.dll [77824]
O44 - LFC:[MD5.62D54F4673A6208C8CC147758122B3C3] - 28/01/2015 - 11:42:14 ---A- . (.Microsoft Corporation - ActiveX Interface Marshaling Library.) -- C:\Windows\System32\actxprxy.dll [2865152]
O44 - LFC:[MD5.39B512C643812FC2D4843C0D4206C759] - 28/01/2015 - 11:42:14 ---A- . (.Microsoft Corporation - Utilitário de Inicialização por Usuário do.) -- C:\Windows\System32\ie4uinit.exe [718848]
O44 - LFC:[MD5.3FA6DC6B29717E32E211C1FD821F2C75] - 28/01/2015 - 11:42:27 ---A- . (.Microsoft Corporation - Serviço de Cache de Fontes do Windows.) -- C:\Windows\System32\FntCache.dll [1345536]
O44 - LFC:[MD5.CC8E86B9C18BCA38D3C467CFD661A466] - 28/01/2015 - 11:42:27 ---A- . (.Microsoft Corporation - Serviços de Tipografia de DirectX da Micros.) -- C:\Windows\System32\DWrite.dll [1975296]
O44 - LFC:[MD5.8BB7548307EE6147137993A410D64387] - 28/01/2015 - 11:42:58 ---A- . (.Microsoft Corporation - Microsoft® C Runtime Library.) -- C:\Windows\System32\msvcr120_clr0400.dll [869544]
O44 - LFC:[MD5.6317C9DB4282CEAA3BAB131BC3839B2A] - 28/01/2015 - 11:43:34 ---A- . (.Microsoft Corporation - DLL da interface de usuário da folha de pro.) -- C:\Windows\System32\compstui.dll [308736]
O44 - LFC:[MD5.9C55CE9707B3CA29A6505BCDCC546390] - 28/01/2015 - 11:43:34 ---A- . (.Microsoft Corporation - Microsoft Fax API Support DLL.) -- C:\Windows\System32\FXSAPI.dll [275968]
O44 - LFC:[MD5.6C118AEDD15FDBEAECC0E85C64B5B86B] - 28/01/2015 - 11:43:35 ---A- . (.Microsoft Corporation - Microsoft Fax Server Extended COM Client In.) -- C:\Windows\System32\FXSCOMEX.dll [615424]
O44 - LFC:[MD5.8758F5DEBD2B950B2D56ED11F9E0B38F] - 28/01/2015 - 11:43:39 ---A- . (.Microsoft Corporation - NTFS Utility DLL.) -- C:\Windows\System32\untfs.dll [545792]
O44 - LFC:[MD5.A8732AFE4DB47114355ABB285ED776D2] - 28/01/2015 - 11:43:41 ---A- . (.Microsoft Corporation - puiapi DLL.) -- C:\Windows\System32\puiapi.dll [187392]
O44 - LFC:[MD5.CFD6DBED27511D7A5FBE33AFA7E6B669] - 28/01/2015 - 11:43:42 ---A- . (.Microsoft Corporation - Bulk File Operations Host Process.) -- C:\Windows\System32\BulkOperationHost.exe [76800]
O44 - LFC:[MD5.118A11C89FAD244A2B85DA7EDC3E9683] - 28/01/2015 - 11:43:42 ---A- . (.Microsoft Corporation - DLL prnntfy.) -- C:\Windows\System32\prnntfy.dll [215552]
O44 - LFC:[MD5.66732C13628BDB1AB0D6FD46027327C2] - 28/01/2015 - 11:43:42 ---A- . (.Microsoft Corporation - Driver de Classe de Armazenamento em Massa.) -- C:\Windows\System32\Drivers\USBSTOR.SYS [148800]
O44 - LFC:[MD5.8CBF1E2761816CFD9D32F8B32531D0FB] - 28/01/2015 - 11:43:42 ---A- . (.Microsoft Corporation - Windows Services Instrumentation Module.) -- C:\Windows\System32\winbici.dll [118272]
O44 - LFC:[MD5.7F23E38C5B6448F91439E4066645191E] - 28/01/2015 - 11:43:43 ---A- . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\Drivers\FWPKCLNT.SYS [428864]
O44 - LFC:[MD5.12C0733F955E15C3C37DD24C9C7D796A] - 28/01/2015 - 11:43:47 ---A- . (.Microsoft Corporation - DLL do Provedor de Impressão DAF.) -- C:\Windows\System32\DafPrintProvider.dll [263680]
O44 - LFC:[MD5.5416C603B6C85CF0698E8A2A1D28BAA2] - 28/01/2015 - 11:43:48 ---A- . (.Microsoft Corporation - DLL de Objetos PrintUI.) -- C:\Windows\System32\puiobj.dll [448512]
O44 - LFC:[MD5.50E96089F9BE352621997143A56C8E76] - 28/01/2015 - 11:43:48 ---A- . (.Microsoft Corporation - Provedor de Impressão do Processo do Client.) -- C:\Windows\System32\win32spl.dll [822272]
O44 - LFC:[MD5.9CE162EB9057CF079736F4DD00FC0D6C] - 28/01/2015 - 11:43:48 ---A- . (.Microsoft Corporation - Serviço WSMan.) -- C:\Windows\System32\WsmSvc.dll [2480128]
O44 - LFC:[MD5.E3FCE2A6B3533D99A3B498504DF9CC47] - 28/01/2015 - 11:43:49 ---A- . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\Drivers\netio.sys [474432]
O44 - LFC:[MD5.CA729FCE295895515A09BD6FF7903DC8] - 28/01/2015 - 11:43:51 ---A- . (.Microsoft Corporation - DLL de Coletor e Fonte MPEG4 do Media Found.) -- C:\Windows\System32\mfmp4srcsnk.dll [836176]
O44 - LFC:[MD5.A208498C5CD750A1743C1AC8162A810F] - 28/01/2015 - 11:43:52 ---A- . (.Microsoft Corporation - Media Foundation Media Engine DLL.) -- C:\Windows\System32\MFMediaEngine.dll [941568]
O44 - LFC:[MD5.1907823D5ACFD75D1D8C0D4318299726] - 28/01/2015 - 11:43:55 ---A- . (.Microsoft Corporation - System Settings Handlers Implementation.) -- C:\Windows\System32\SettingsHandlers.dll [2714112]
O44 - LFC:[MD5.BCE66E78D388875B87286CA091E7075F] - 28/01/2015 - 11:44:00 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [7484224]
O44 - LFC:[MD5.1D303CE5BCBD5B80BBA08321F28A3F86] - 28/01/2015 - 11:44:02 ---A- . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\Windows\System32\shell32.dll [21197152]
O44 - LFC:[MD5.CCB3A2BB60FE5073F2DEA63FE83CF8FE] - 28/01/2015 - 11:44:02 ---A- . (.Microsoft Corporation - Driver TCP/IP.) -- C:\Windows\System32\Drivers\tcpip.sys [2497344]
O44 - LFC:[MD5.A92EF73B02686B7E6F070B486512DB88] - 28/01/2015 - 11:44:03 ---A- . (...) -- C:\Windows\System32\ApnDatabase.xml [389176]
O44 - LFC:[MD5.C88B63FE96DB4BCED65DD442BC8E77F5] - 28/01/2015 - 11:44:03 ---A- . (.Microsoft Corporation - DLL do spooler local.) -- C:\Windows\System32\localspl.dll [1053184]
O44 - LFC:[MD5.C4306ADC38939CAC60EA38AAD9F170C0] - 28/01/2015 - 11:44:03 ---A- . (.Microsoft Corporation - TWINUI.) -- C:\Windows\System32\twinui.dll [13424128]
O44 - LFC:[MD5.84549E8C8BF76B293A7E625A98D4BCF9] - 28/01/2015 - 11:44:10 ---A- . (.Microsoft Corporation - Gerenciador de Objetos 2.) -- C:\Windows\System32\packager.dll [81408]
O44 - LFC:[MD5.5D4A403DAE434FBA11779496EAFBDDE8] - 28/01/2015 - 11:44:25 ---A- . (.Microsoft Corporation - AD Harvest Sites and Subnets Service.) -- C:\Windows\System32\adhsvc.dll [75776]
O44 - LFC:[MD5.E0927EFA25D473367C3341B9F5969779] - 28/01/2015 - 11:44:25 ---A- . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\Drivers\bridge.sys [115712]
O44 - LFC:[MD5.0DD29E5328436D51517316CD6D3BACCA] - 28/01/2015 - 11:44:25 ---A- . (.Microsoft Corporation - Provedor de Proxy PCSV para dispositivos.) -- C:\Windows\System32\pcsvDevice.dll [286208]
O44 - LFC:[MD5.36F977EDAE6CEE96CE6409B2B16765B4] - 28/01/2015 - 11:44:25 ---A- . (.Microsoft Corporation - Proximity Service Implementation.) -- C:\Windows\System32\ProximityService.dll [290816]
O44 - LFC:[MD5.73F269436228D5625E83A1EAF3549F58] - 28/01/2015 - 11:44:26 ---A- . (.Microsoft Corporation - Proxy Manager.) -- C:\Windows\System32\httpprxm.dll [118272]
O44 - LFC:[MD5.0B1A9F6F9D2891C0F8783C0444D27DD0] - 28/01/2015 - 11:44:26 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [1057280]
O44 - LFC:[MD5.E325BCD68EC0CF2E2EDD0AB7CC17C698] - 28/01/2015 - 11:44:26 ---A- . (.Microsoft Corporation - Serviço de Infraestrutura de Tarefas de Seg.) -- C:\Windows\System32\bisrv.dll [267776]
O44 - LFC:[MD5.FD4EA8E9232ADD51DC31C295DDEF2768] - 28/01/2015 - 11:44:27 ---A- . (.Microsoft Corporation - Agente de Eventos do Sistema.) -- C:\Windows\System32\SystemEventsBrokerServer.dll [287744]
O44 - LFC:[MD5.ABB028BAB78E7B4AFE374F8246F6CCB6] - 28/01/2015 - 11:44:28 ---A- . (.Microsoft Corporation - DLL da API LDAP Win32.) -- C:\Windows\System32\Wldap32.dll [359424]
O44 - LFC:[MD5.10CE7F7704E293F6CC6E0AF51DBFD95A] - 28/01/2015 - 11:44:29 ---A- . (.Microsoft Corporation - SearchFolder.) -- C:\Windows\System32\SearchFolder.dll [1106432]
O44 - LFC:[MD5.ACFEE9487693C2BD573DFCA71D98E17C] - 28/01/2015 - 11:44:29 ---A- . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em u.) -- C:\Windows\System32\iphlpsvc.dll [914432]
O44 - LFC:[MD5.5053FE9043FB84D71B04EFC7D5DA13CF] - 28/01/2015 - 11:44:30 ---A- . (.Microsoft Corporation - DLL de nível do NT.) -- C:\Windows\System32\ntdll.dll [1710184]
O44 - LFC:[MD5.2ECA23663D13100032E09062C743C70D] - 28/01/2015 - 11:44:30 ---A- . (.Microsoft Corporation - Sistema de Propriedades Microsoft.) -- C:\Windows\System32\propsys.dll [1507648]
O44 - LFC:[MD5.37C1CBCB3F420C754E86E3EC313D436D] - 28/01/2015 - 11:44:32 ---A- . (.Microsoft Corporation - DLL cliente da API BASE do Windows NT.) -- C:\Windows\System32\KernelBase.dll [1112512]
O44 - LFC:[MD5.F58FBEA392B663B936E62939A877CA80] - 28/01/2015 - 11:44:32 ---A- . (.Microsoft Corporation - OneDrive Sync Engine.) -- C:\Windows\System32\SkyDrive.exe [1120768]
O44 - LFC:[MD5.8A522BBE4E06586C57E5D9DC50FB88B0] - 28/01/2015 - 11:44:35 ---A- . (.Microsoft Corporation - Cliente ActiveX dos Serviços de Área de Tra.) -- C:\Windows\System32\mstscax.dll [6649344]
O44 - LFC:[MD5.1676B06421492B439A9E60C55692A921] - 28/01/2015 - 11:44:37 ---A- . (.Microsoft Corporation - Windows.UI.Search.) -- C:\Windows\System32\Windows.UI.Search.dll [8757760]
O44 - LFC:[MD5.57CA779C19C2F224BE0C5EFC40F54B60] - 28/01/2015 - 11:44:38 ---A- . (.Microsoft Corporation - Microsoft OneDrive Sync Engine.) -- C:\Windows\System32\SyncEngine.dll [4758528]
O44 - LFC:[MD5.66CBCDDEF429E5BA83C3288EEB0771A6] - 28/01/2015 - 11:44:38 ---A- . (.Microsoft Corporation - Telemetry Library for the OneDrive client.) -- C:\Windows\System32\SkyDriveTelemetry.dll [717824]
O44 - LFC:[MD5.7DDE896B21DA5E893559051F1AD69F2B] - 28/01/2015 - 11:44:41 ---A- . (.Microsoft Corporation - DLL de Tempo de Execução da Estrutura de Te.) -- C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll [249344]
O44 - LFC:[MD5.65392F3F3F65E4C6CC82A0F4F8A0B051] - 28/01/2015 - 11:44:41 ---A- . (.Microsoft Corporation - Driver de HUB USB3.) -- C:\Windows\System32\Drivers\USBHUB3.SYS [468288]
O44 - LFC:[MD5.3014CE5846A486C624E3E2CEB8C3290C] - 28/01/2015 - 11:44:41 ---A- . (.Microsoft Corporation - Extensão de Shell do Microsoft OneDrive.) -- C:\Windows\System32\SkyDriveShell.dll [286208]
O44 - LFC:[MD5.30293301B14D0D11D086B09831F5FE0D] - 28/01/2015 - 11:44:44 ---A- . (.Microsoft Corporation - WSShared DLL.) -- C:\Windows\System32\WSShared.dll [920064]
O44 - LFC:[MD5.B31C4917EC5EADE24A90DDAF37EA00E0] - 28/01/2015 - 11:46:30 ---A- . (.Microsoft Corporation - Driver Win32 multiusuário.) -- C:\Windows\System32\win32k.sys [4182016]
O44 - LFC:[MD5.788C7D910267DDCD675DF4AB01961265] - 28/01/2015 - 11:46:45 ---A- . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll [259584]
O44 - LFC:[MD5.E87F8EC00FEEF700E61F6989D88A8BC2] - 28/01/2015 - 11:46:47 ---A- . (.Microsoft Corporation - Pacote de Segurança Kerberos.) -- C:\Windows\System32\kerberos.dll [991232]
O44 - LFC:[MD5.B7CC32E00C5C5152D221DF182827F58E] - 28/01/2015 - 12:29:38 ---A- . (...) -- C:\Windows\System32\srms.dat [50745]
O44 - LFC:[MD5.71BAEAFD05B3040173F5BBEA2CFE9607] - 28/01/2015 - 12:31:27 ---A- . (.Microsoft Corporation - Mecanismo de Redefinição do Microsoft Windo.) -- C:\Windows\System32\reseteng.dll [997888]
O44 - LFC:[MD5.35BF5C5F5E3C9902C98978C7640574DA] - 28/01/2015 - 12:32:09 ---A- . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\Drivers\vwififlt.sys [71680]
O44 - LFC:[MD5.D3883FBCA97D10C8A39632D6CDDC6E85] - 28/01/2015 - 12:33:01 ---A- . (.Microsoft Corporation - Cliente DHCPv6.) -- C:\Windows\System32\dhcpcsvc6.dll [65024]
O44 - LFC:[MD5.DEA76F90F9777E3427D70E380222B23B] - 28/01/2015 - 12:33:06 ---A- . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\IKEEXT.DLL [1063424]
O44 - LFC:[MD5.7E1EBDB3424337ABB553F249A7811D94] - 28/01/2015 - 12:33:45 ---A- . (.Microsoft Corporation - Serviço do Cliente DHCP.) -- C:\Windows\System32\dhcpcsvc.dll [87552]
O44 - LFC:[MD5.2616E8E9C8B66A67CFB6197E9517A2F2] - 28/01/2015 - 12:34:02 ---A- . (.Microsoft Corporation - Microsoft Robocopy.) -- C:\Windows\System32\Robocopy.exe [123392]
O44 - LFC:[MD5.65ED7B9CFEA893DF7748D5FF692690DE] - 28/01/2015 - 12:34:12 ---A- . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\Drivers\vwifimp.sys [38912]
O44 - LFC:[MD5.FBB1841434072FFA76E4AD287448E34A] - 28/01/2015 - 12:35:03 ---A- . (.Microsoft Corporation - WMI SDK Provider Framework.) -- C:\Windows\System32\framedyn.dll [262656]
O44 - LFC:[MD5.1824052F17B12B5D7B21445B869EE9F2] - 28/01/2015 - 12:35:27 ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\ncobjapi.dll [71168]
O44 - LFC:[MD5.674A4702E4E144E8710ED1A2EC6DD049] - 28/01/2015 - 12:35:37 ---A- . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) -- C:\Windows\System32\Drivers\agilevpn.sys [96768]
O44 - LFC:[MD5.20FB137ADDE1255F15F265A7BD9579BE] - 28/01/2015 - 12:35:42 ---A- . (.Microsoft Corporation - Mecanismo de Filtragem Básica.) -- C:\Windows\System32\BFE.DLL [827392]
O44 - LFC:[MD5.E07C80468D0C599BFF01D9D4EC7AEDC3] - 28/01/2015 - 12:36:21 ---A- . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [339456]
O44 - LFC:[MD5.10AC9494ECE22A2362E4E4D98C528D01] - 28/01/2015 - 12:36:32 ---A- . (.Microsoft Corporation - Cliente DHCPv6.) -- C:\Windows\System32\dhcpcore6.dll [271872]
O44 - LFC:[MD5.6B374D279DC423FE69DB8DD1401E84FC] - 28/01/2015 - 12:37:17 ---A- . (.Microsoft Corporation - WMI SDK Provider Framework.) -- C:\Windows\System32\framedynos.dll [301056]
O44 - LFC:[MD5.7A1A3F213CDB3363D179D5014272025D] - 28/01/2015 - 12:37:23 ---A- . (.Microsoft Corporation - Minirdr SMB do Windows NT.) -- C:\Windows\System32\Drivers\mrxsmb.sys [402432]
O44 - LFC:[MD5.05DE04005CE0D84D0E6AD21CAEB369C6] - 28/01/2015 - 12:38:48 ---A- . (.Microsoft Corporation - Serviço do Cliente DHCP.) -- C:\Windows\System32\dhcpcore.dll [353280]
O44 - LFC:[MD5.98D0985521BF8F7086EA9C860898A1EE] - 28/01/2015 - 12:38:58 ---A- . (.Microsoft Corporation - Windows BitLocker Drive Encryption API.) -- C:\Windows\System32\fveapi.dll [721408]
O44 - LFC:[MD5.EA432A85ABF371E14FB364D5F4405897] - 28/01/2015 - 12:39:28 ---A- . (.Microsoft Corporation - VPNIKE Protocol Engine - Test dll.) -- C:\Windows\System32\vpnike.dll [403968]
O44 - LFC:[MD5.C1E44A99F7CF8C3A08CD5ADDF451636C] - 28/01/2015 - 12:40:33 ---A- . (.Microsoft Corporation - Direct3D 9 Runtime.) -- C:\Windows\System32\d3d9.dll [2125344]
O44 - LFC:[MD5.BB7F878413AD3C2E7E89C96193D405DF] - 28/01/2015 - 12:51:36 ---A- . (.Microsoft Corporation - Driver Installation Module.) -- C:\Windows\System32\drvcfg.exe [57856]
O44 - LFC:[MD5.8E472AA2E916417B55BC1E6727957453] - 28/01/2015 - 12:51:36 ---A- . (.Microsoft Corporation - Módulo de Instalação de Driver.) -- C:\Windows\System32\drvinst.exe [110592]
O44 - LFC:[MD5.6DBE73C09215E281F4283641144110A5] - 28/01/2015 - 13:16:24 ---A- . (.Microsoft Corporation - Windows Presentation Foundation Terminal Se.) -- C:\Windows\System32\TsWpfWrp.exe [35480]
O44 - LFC:[MD5.93645AEBE163230A2ED5050C14AE6603] - 28/01/2015 - 13:20:24 ---A- . (.Microsoft Corporation - MSXML 3.0.) -- C:\Windows\System32\msxml3.dll [2149376]
O44 - LFC:[MD5.F5BA843DE3475B8D7FD5AFC21857A7C1] - 28/01/2015 - 13:22:32 ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1970432]
O44 - LFC:[MD5.668417ED63F9FBE7DD8D7A54B04279DA] - 28/01/2015 - 14:42:34 ---A- . (.Microsoft Corporation - File Risk Estimation.) -- C:\Windows\System32\winshfhc.dll [14336]
O44 - LFC:[MD5.0359607177E5E9F6041136CC0A5CB0B6] - 28/01/2015 - 14:43:19 ---A- . (.Microsoft Corporation - Microsoft antimalware boot driver.) -- C:\Windows\System32\Drivers\WdBoot.sys [35320]
O44 - LFC:[MD5.4AD874CDC812EC156265E451B6B09DAB] - 28/01/2015 - 14:43:37 ---A- . (.Microsoft Corporation - Microsoft Network Realtime Inspection Drive.) -- C:\Windows\System32\Drivers\WdNisDrv.sys [114496]
O44 - LFC:[MD5.DE8D12B4C3F55FA2C5E9774314F6C58A] - 28/01/2015 - 14:43:56 ---A- . (.Microsoft Corporation - Microsoft antimalware file system filter dr.) -- C:\Windows\System32\Drivers\WdFilter.sys [258368]
O44 - LFC:[MD5.F0A117D19873FCDF801F082F33BFBB6C] - 28/01/2015 - 14:44:50 ---A- . (.Microsoft Corporation - DLL de cliente API de usuário Windows para.) -- C:\Windows\System32\user32.dll [1519488]
O44 - LFC:[MD5.29A888F3136B2643E22113B5422B46F9] - 28/01/2015 - 14:51:37 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [87040]
O44 - LFC:[MD5.6BC31FB4E24A962C98801D3687A984C0] - 28/01/2015 - 14:55:20 ---A- . (.Microsoft Corporation - Biblioteca de Sincronização via Web da Prot.) -- C:\Windows\System32\WpcWebSync.dll [2861056]
O44 - LFC:[MD5.E7DE316FEEFC79327CFAD8F527979CC0] - 28/01/2015 - 14:55:55 ---A- . (.Microsoft Corporation - Biblioteca de Configurações dos Controles d.) -- C:\Windows\System32\Wpc.dll [3118080]
O44 - LFC:[MD5.E2F4125BFAC99244088324A1841C0B83] - 28/01/2015 - 14:57:11 ---A- . (.Microsoft Corporation - Monitor de Proteção para a Família.) -- C:\Windows\System32\WpcMon.exe [3048880]
O44 - LFC:[MD5.D1A2E993DB1867C79177CCC9DB6337D0] - 28/01/2015 - 15:07:23 ---A- . (.Microsoft Corporation - IU de consentimento para aplicativos admini.) -- C:\Windows\System32\consent.exe [116032]
O44 - LFC:[MD5.034ED41F13D9C1845C1E081F05B640DB] - 28/01/2015 - 15:07:23 ---A- . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\Windows\System32\appinfo.dll [110080]
O44 - LFC:[MD5.D0C15BC83B3D0AF4F9B1D70216D91794] - 28/01/2015 - 15:07:41 ---A- . (.Microsoft Corporation - Windows® installer.) -- C:\Windows\System32\msihnd.dll [428032]
O44 - LFC:[MD5.EF745B98D81B8C462DB99FC8B5C4322A] - 28/01/2015 - 15:09:06 ---A- . (.Microsoft Corporation - Windows Installer.) -- C:\Windows\System32\msi.dll [3320320]
O44 - LFC:[MD5.D5B41A0C38408814A3E9BAC8C82B2E5B] - 28/01/2015 - 15:09:17 ---A- . (.Microsoft Corporation - Interface do Usuário da Autenticação do Win.) -- C:\Windows\System32\authui.dll [2773504]
O44 - LFC:[MD5.F0CB6DB513CAC393D04A0FCE0A59E1BF] - 28/01/2015 - 15:28:26 ---A- . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\Windows\System32\Drivers\ahcache.sys [75776]
O44 - LFC:[MD5.DB32958F0E704EFBF7F15161A569E39F] - 28/01/2015 - 15:29:07 ---A- . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\Drivers\mrxdav.sys [140800]
O44 - LFC:[MD5.87CEF71F9D5951C9379D2F956C07C37D] - 28/01/2015 - 15:29:58 ---A- . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\System32\gdi32.dll [1336624]
O44 - LFC:[MD5.25EE65F2FA154EDED0E87354311FB1E2] - 28/01/2015 - 15:33:13 ---A- . (.Microsoft Corporation - Remote Access PPP EAP-TLS.) -- C:\Windows\System32\rastls.dll [590336]
O44 - LFC:[MD5.83AEDC4636606B145851723AE7385781] - 28/01/2015 - 15:57:22 ---A- . (.Microsoft Corporation - DLL do Provedor de Status da Instalação do.) -- C:\Windows\System32\DeviceSetupStatusProvider.dll [34304]
O44 - LFC:[MD5.D3AE5DB16EAF913860EC28654CE00E6B] - 28/01/2015 - 16:18:08 ---A- . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\Windows\System32\schedsvc.dll [1212928]
O44 - LFC:[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - 28/01/2015 - 16:18:46 ---A- . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\Drivers\afd.sys [563200]
O44 - LFC:[MD5.19424364D8C03B990C4281BE53963FD0] - 28/01/2015 - 16:44:41 ---A- . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [225280]
O44 - LFC:[MD5.454978FB3D24DE5C4199162D5F81FBEE] - 28/01/2015 - 16:47:47 ---A- . (.Microsoft Corporation - Biblioteca Principal de DWM da Microsoft.) -- C:\Windows\System32\dwmcore.dll [2133504]
O44 - LFC:[MD5.313DCE665B57000B18CB26C6B6A10DFE] - 28/01/2015 - 16:47:52 ---A- . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys [1557848]
O44 - LFC:[MD5.59EAFAE3A34B4925990A2E679CA91C5B] - 28/01/2015 - 16:47:55 ---A- . (.Microsoft Corporation - DirectX Graphics Infrastructure.) -- C:\Windows\System32\dxgi.dll [517528]
O44 - LFC:[MD5.9A108C0A3092110F4651B3AFB9CC7B3D] - 28/01/2015 - 16:58:13 ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\oleaut32.dll [789184]
O44 - LFC:[MD5.A8484FB640E044858BA19FB4F13DD4CE] - 28/01/2015 - 17:15:57 ---A- . (.Microsoft Corporation - DLL de eventos de auditoria de segurança.) -- C:\Windows\System32\msaudite.dll [154112]
O44 - LFC:[MD5.9F08A6608F98B5407E7DDBCF306573EF] - 28/01/2015 - 17:15:58 ---A- . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\Drivers\rdpvideominiport.sys [27456]
O44 - LFC:[MD5.3D2D2EA099D98FE6B94C7D8C7992C08C] - 28/01/2015 - 17:15:58 ---A- . (.Microsoft Corporation - Microsoft RemoteFX VM Transport.) -- C:\Windows\System32\rfxvmt.dll [40448]
O44 - LFC:[MD5.D7B23B3154508256C9F434EF9B65B91D] - 28/01/2015 - 17:15:58 ---A- . (.Microsoft Corporation - UMRDP Display Driver.) -- C:\Windows\System32\rdpudd.dll [131584]
O44 - LFC:[MD5.91E59FCB3B32DD84E5DCDA2EA1583807] - 28/01/2015 - 17:15:59 ---A- . (.Microsoft Corporation - DLL do Esquema de auditoria de segurança.) -- C:\Windows\System32\adtschema.dll [736768]
O44 - LFC:[MD5.6D2EE96150E35B9EA49F2B481DE0369A] - 28/01/2015 - 17:15:59 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [177472]
O44 - LFC:[MD5.488CEA4F1B4D2446FFB7A94E3CB385FE] - 28/01/2015 - 17:16:00 ---A- . (.Microsoft Corporation - Cliente dos Serviços de Certificados do Act.) -- C:\Windows\System32\certcli.dll [445440]
O44 - LFC:[MD5.4E1207CE16E615B0B7A70DC889F4500E] - 28/01/2015 - 17:16:00 ---A- . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\Drivers\cng.sys [563976]
O44 - LFC:[MD5.1D25CC0A9C480C5D56A5A6CF2B5DEB99] - 28/01/2015 - 17:16:02 ---A- . (.Microsoft Corporation - TS RDPCore DLL.) -- C:\Windows\System32\rdpcorets.dll [3547648]
O44 - LFC:[MD5.949E590B76018E4523FC71CE510ED9ED] - 28/01/2015 - 17:16:04 ---A- . (.Microsoft Corporation - DLL do servidor LSA.) -- C:\Windows\System32\lsasrv.dll [1441792]
O44 - LFC:[MD5.1BB9CC78C91536CBA7B04B61ED0F85C4] - 28/01/2015 - 17:27:20 ---A- . (.Microsoft Corporation - Tempo de Execução da Chamada de Procediment.) -- C:\Windows\System32\rpcrt4.dll [1273184]
O44 - LFC:[MD5.6DE50D5592C6EE18C87B0C2EEEDC1621] - 28/01/2015 - 17:27:39 ---A- . (.Microsoft Corporation - DPAPI Server.) -- C:\Windows\System32\dpapisrv.dll [185856]
O44 - LFC:[MD5.622928F5A8045F8122F10561D6C35ED0] - 28/01/2015 - 17:27:39 ---A- . (.Microsoft Corporation - Microsoft SChannel Provider.) -- C:\Windows\System32\ncryptsslp.dll [104336]
O44 - LFC:[MD5.F0CE4A653EEBA09509EAF93AE2226FA9] - 28/01/2015 - 17:27:39 ---A- . (.Microsoft Corporation - Provedor de Segurança TLS/SSL.) -- C:\Windows\System32\schannel.dll [426496]
O44 - LFC:[MD5.ACDBE1ED38167C8B01B8F63161BB2CEA] - 28/01/2015 - 17:27:47 ---A- . (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\explorer.exe [2374784]
O44 - LFC:[MD5.04AE20974DF91DC7B9075FC5A126B77C] - 28/01/2015 - 17:27:47 ---A- . (.Microsoft Corporation - Windows User Experience Session Initializat.) -- C:\Windows\System32\UXInit.dll [68096]
O44 - LFC:[MD5.00CD1254837739E310505EBCB19F7971] - 28/01/2015 - 17:27:48 ---A- . (.Microsoft Corporation - Gerenciador de Janelas da Área de Trabalho.) -- C:\Windows\System32\uDWM.dll [796672]
O44 - LFC:[MD5.8DF1254093B5C354CE725EB6B9B0DE19] - 28/01/2015 - 17:27:50 ---A- . (.Microsoft Corporation - GPIO Class Extension Driver.) -- C:\Windows\System32\Drivers\msgpioclx.sys [146752]
O44 - LFC:[MD5.DA947D89F64B72A40F678AAAE76F7564] - 28/01/2015 - 17:27:52 ---A- . (.Microsoft Corporation - DLL da interface de usuário do monitor de p.) -- C:\Windows\System32\tcpmon.dll [205824]
O44 - LFC:[MD5.E09BF40AA766B183F0F385C96B37D9E5] - 28/01/2015 - 17:27:52 ---A- . (.Microsoft Corporation - Monitor de Porta de Impressora WSD.) -- C:\Windows\System32\WSDMon.dll [299520]
O44 - LFC:[MD5.93B0550500D1BD86CBAB9C4CC6B6A356] - 28/01/2015 - 17:30:27 ---A- . (.Microsoft Corporation - Ferramentas de Remoção de Software Mal-Inte.) -- C:\Windows\System32\MRT.exe [113365784]
O44 - LFC:[MD5.26C43960C99EE861A5D0EDC4DCF3B1C3] - 29/01/2015 - 10:40:15 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [129752]
O44 - LFC:[MD5.3D748E5558FD9A9F03182CB2330698DC] - 29/01/2015 - 15:53:02 ---A- . (.Microsoft Corporation - Gerenciador de Conexões Remotas do Servidor.) -- C:\Windows\System32\termsrv.dll [1018880]
O44 - LFC:[MD5.C42C0453D2968E579F92D134BBBD8FEF] - 29/01/2015 - 23:31:20 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.68270DE9415C8F8139242D38417B49BE] - 30/01/2015 - 10:20:05 ---A- . (.Microsoft Corporation - Tatar Keyboard Layout.) -- C:\Windows\System32\KBDTT102.DLL [7168]
O44 - LFC:[MD5.D8683834163E00E252CAC57BB6025036] - 30/01/2015 - 10:20:05 ---A- . (.Microsoft Corporation - Windows Update WUDriver Stub.) -- C:\Windows\System32\wudriver.dll [93696]
O44 - LFC:[MD5.B279922BCFD0E178068B159D85C5CDBE] - 30/01/2015 - 10:20:06 ---A- . (.Microsoft Corporation - System Settings Admin Flow XAML UI Implemen.) -- C:\Windows\System32\SystemSettingsAdminFlowUI.dll [2100736]
O44 - LFC:[MD5.A5141DD172927F04732F5B6BFBE49C15] - 30/01/2015 - 10:20:07 ---A- . (.Microsoft Corporation - Windows Wireless LAN 802.11 MSM Security Mo.) -- C:\Windows\System32\wlansec.dll [443904]
O44 - LFC:[MD5.4F6203CBBEFB9FBFA859246682849A24] - 30/01/2015 - 10:20:08 ---A- . (.Microsoft Corporation - Gerenciador de Mídia WWan.) -- C:\Windows\System32\wwanmm.dll [1144320]
O44 - LFC:[MD5.997E5E28492F02036E5C7BA6DB66ABDC] - 30/01/2015 - 10:20:08 ---A- . (.Microsoft Corporation - Tatar (Legacy) Keyboard Layout.) -- C:\Windows\System32\KBDTAT.DLL [7168]
O44 - LFC:[MD5.933C63C9003379F56BA4AF4149440FC8] - 30/01/2015 - 10:20:08 ---A- . (.Microsoft Corporation - Volume SCA.) -- C:\Windows\System32\SndVolSSO.dll [226304]
O44 - LFC:[MD5.0AC5A816A01D0115588D4B997842780E] - 30/01/2015 - 10:20:11 ---A- . (.Microsoft Corporation - Bashkir Keyboard Layout.) -- C:\Windows\System32\KBDBASH.DLL [7168]
O44 - LFC:[MD5.A4DE7868879498A4E4CBB12788FAA3E8] - 30/01/2015 - 10:20:11 ---A- . (.Microsoft Corporation - Bluetooth Usermode Api host.) -- C:\Windows\System32\BluetoothApis.dll [105472]
O44 - LFC:[MD5.454A0735E836FBC31C064FED6C120B46] - 30/01/2015 - 10:20:11 ---A- . (.Microsoft Corporation - Russia(Typewriter) Keyboard Layout.) -- C:\Windows\System32\KBDRU1.DLL [7168]
O44 - LFC:[MD5.6A9650BDC13F1A770F20E7B99D29EE3D] - 30/01/2015 - 10:20:11 ---A- . (.Microsoft Corporation - Russian Keyboard Layout.) -- C:\Windows\System32\KBDRU.DLL [6656]
O44 - LFC:[MD5.3429360674DA1E70F638924A6D5985CC] - 30/01/2015 - 10:20:11 ---A- . (.Microsoft Corporation - Sakha - Russia Keyboard Layout.) -- C:\Windows\System32\KBDYAK.DLL [7168]
O44 - LFC:[MD5.EB2BB6EC7AEBBDD04FAB8E8D6FCEDAA6] - 30/01/2015 - 10:20:12 ---A- . (.Microsoft Corp. - Desfragmentador de disco do Windows.) -- C:\Windows\System32\Defrag.exe [183808]
O44 - LFC:[MD5.2067AF0531ACD5D28BD49DB30DF109CE] - 30/01/2015 - 10:20:12 ---A- . (.Microsoft Corporation - Russian - Mnemonic Keyboard Layout.) -- C:\Windows\System32\KBDRUM.DLL [8192]
O44 - LFC:[MD5.CB9CEAB473897BE1E8C827D4F4EB1311] - 30/01/2015 - 10:20:13 ---A- . (.Microsoft Corporation - Miniaplicativo Gerenciamento de energia do.) -- C:\Windows\System32\powercfg.cpl [207360]
O44 - LFC:[MD5.A7762A36F92E57E41B0356EF5C672473] - 30/01/2015 - 10:20:18 ---A- . (.Microsoft Corporation - DLL Windows.Devices.Bluetooth.) -- C:\Windows\System32\Windows.Devices.Bluetooth.dll [659968]
O44 - LFC:[MD5.041A999E4FF9A7CDBE67357751881FB8] - 30/01/2015 - 10:20:18 ---A- . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\Windows\System32\browser.dll [134144]
O44 - LFC:[MD5.3A80675FF8524B09817000B6A2E35B7A] - 30/01/2015 - 10:20:18 ---A- . (.Microsoft Corporation - Windows WLAN AutoConfig Service PAL DLL.) -- C:\Windows\System32\wlansvcpal.dll [18432]
O44 - LFC:[MD5.2DEA7EACD3471CA4EDCE55CBCE96E496] - 30/01/2015 - 10:20:19 ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\PrintDialogs.dll [557056]
O44 - LFC:[MD5.69AF7212845FFCD0AA1F0FC5D51FB809] - 30/01/2015 - 10:20:19 ---A- . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\System32\wshbth.dll [63488]
O44 - LFC:[MD5.1E01725D557B5325E8C99F712E7D4A7E] - 30/01/2015 - 10:20:20 ---A- . (.Microsoft Corporation - Windows Update client proxy stub 2.) -- C:\Windows\System32\wups2.dll [50688]
O44 - LFC:[MD5.53F4FC66B94804BBF2016922CD826891] - 30/01/2015 - 10:20:21 ---A- . (.Microsoft Corporation - Central de Ações.) -- C:\Windows\System32\ActionCenter.dll [878592]
O44 - LFC:[MD5.AEDF08DDF4EA929FEDBC0A1CCF01F287] - 30/01/2015 - 10:20:21 ---A- . (.Microsoft Corporation - DLL de API do Cliente de Configuração Autom.) -- C:\Windows\System32\wlanapi.dll [296960]
O44 - LFC:[MD5.B540693968BCA57F595A7B08DB4B46C3] - 30/01/2015 - 10:20:21 ---A- . (.Microsoft Corporation - Microsoft Enhanced Cryptographic Provider.) -- C:\Windows\System32\rsaenh.dll [216368]
O44 - LFC:[MD5.3AB9868E0E78AD9CD501B83D7C293125] - 30/01/2015 - 10:20:21 ---A- . (.Microsoft Corporation - Windows Update.) -- C:\Windows\System32\wuauclt.exe [54752]
O44 - LFC:[MD5.31C2E53FE0C039C1BF0F15154D8596E7] - 30/01/2015 - 10:20:22 ---A- . (.Microsoft Corporation - AppX Sysprep Provider.) -- C:\Windows\System32\AppxSysprep.dll [53248]
O44 - LFC:[MD5.6ECFFE49AA43A74DC15701EFE6355621] - 30/01/2015 - 10:20:22 ---A- . (.Microsoft Corporation - DLL do Agente de Atividade de Área de Traba.) -- C:\Windows\System32\dab.dll [92160]
O44 - LFC:[MD5.9C096BF5E10CA8BFA56F32522A89FAF1] - 30/01/2015 - 10:20:22 ---A- . (.Microsoft Corporation - DRIVER WMI IPMI.) -- C:\Windows\System32\Drivers\IPMIDrv.sys [79872]
O44 - LFC:[MD5.FA86C3F979EF9CCCCED109B05DEBDD46] - 30/01/2015 - 10:20:22 ---A- . (.Microsoft Corporation - Fluxos de Conexão WAN Sem Fio.) -- C:\Windows\System32\wwanconn.dll [432640]
O44 - LFC:[MD5.28E8D340402C130427F2901004B7FA99] - 30/01/2015 - 10:20:22 ---A- . (.Microsoft Corporation - Objeto de serviço do shell de Systray.) -- C:\Windows\System32\stobject.dll [321536]
O44 - LFC:[MD5.2B1C2CB5C97962C521CD806F0C86D2FE] - 30/01/2015 - 10:20:22 ---A- . (.Microsoft Corporation - Windows Connection Service Provider DLL.) -- C:\Windows\System32\wcmcsp.dll [102912]
O44 - LFC:[MD5.0AB5085FE30F8F6942A2126BCFC1A606] - 30/01/2015 - 10:20:23 ---A- . (.Microsoft Corporation - Fluxos administrativos de configurações do.) -- C:\Windows\System32\SystemSettingsAdminFlows.exe [263400]
O44 - LFC:[MD5.1DD05F4857C2188744B9E864658949DD] - 30/01/2015 - 10:20:23 ---A- . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\Drivers\ks.sys [295424]
O44 - LFC:[MD5.0A3E1B697F6ACB7BC1C898DC14A96EC7] - 30/01/2015 - 10:20:23 ---A- . (.Microsoft Corporation - Storage Management Provider for Spaces.) -- C:\Windows\System32\mispace.dll [1287680]
O44 - LFC:[MD5.91ED124E261EA8FAA1C0FFDF2A71B0C4] - 30/01/2015 - 10:20:24 ---A- . (.Microsoft Corporation - Enumerador NT Plug and Play PCI.) -- C:\Windows\System32\Drivers\pci.sys [280384]
O44 - LFC:[MD5.CCD0DF268D9C9F5287B66565B4258FD6] - 30/01/2015 - 10:20:24 ---A- . (.Microsoft Corporation - Windows Update client proxy stub.) -- C:\Windows\System32\wups.dll [59392]
O44 - LFC:[MD5.91B18D7A1702ED589E67C6C81052B955] - 30/01/2015 - 10:20:25 ---A- . (.Microsoft Corporation - DLL do Serviço WebDAV.) -- C:\Windows\System32\WebClnt.dll [226816]
O44 - LFC:[MD5.572EBBCDBBA56736F4C0B5487AE7BFA5] - 30/01/2015 - 10:20:26 ---A- . (.Microsoft Corporation - NPS NAP Provider.) -- C:\Windows\System32\iasnap.dll [220160]
O44 - LFC:[MD5.97F24AEACAD9C9038BEC5B2BA1ADA94C] - 30/01/2015 - 10:20:27 ---A- . (.Microsoft Corporation - Extensão de Shell de Pastas de Trabalho da.) -- C:\Windows\System32\WorkFoldersShell.dll [187392]
O44 - LFC:[MD5.FD807B56AECFD89E4A46960C261D78BF] - 30/01/2015 - 10:20:27 ---A- . (.Microsoft Corporation - GPEdit.) -- C:\Windows\System32\gpedit.dll [1089024]
O44 - LFC:[MD5.1A5835F2E6B49A83F0AEAD17B4537AF7] - 30/01/2015 - 10:20:27 ---A- . (.Microsoft Corporation - Microsoft GDI+.) -- C:\Windows\System32\GdiPlus.dll [1656832]
O44 - LFC:[MD5.A6CB3CBF88DF671AC85FA9AABC33137F] - 30/01/2015 - 10:20:28 ---A- . (.Microsoft Corporation - API do Gerenciador de Janelas da Área de Tr.) -- C:\Windows\System32\dwmapi.dll [125472]
O44 - LFC:[MD5.20657ACF2AE5B2E25EEFC597A34AFDED] - 30/01/2015 - 10:20:28 ---A- . (.Microsoft Corporation - Experiência de Usuário Cliente do Windows U.) -- C:\Windows\System32\wucltux.dll [1705472]
O44 - LFC:[MD5.7DEAD28D8FB9BCAE4A153A57338315E7] - 30/01/2015 - 10:20:28 ---A- . (.Microsoft Corporation - MCI API DLL.) -- C:\Windows\System32\winmm.dll [123920]
O44 - LFC:[MD5.CCC106273D4265A9091AA7B619DCC5DA] - 30/01/2015 - 10:20:28 ---A- . (.Microsoft Corporation - Windows.Networking DLL.) -- C:\Windows\System32\Windows.Networking.dll [595456]
O44 - LFC:[MD5.1922AAE64BCD761A0377F6981FC67736] - 30/01/2015 - 10:20:28 ---A- . (.Microsoft Corporation - twinapi.) -- C:\Windows\System32\twinapi.dll [721408]
O44 - LFC:[MD5.D4B7ED39C7900384D9E5C1283F1E7926] - 30/01/2015 - 10:20:29 ---A- . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\Drivers\hdaudbus.sys [76800]
O44 - LFC:[MD5.C910E5D18958914A66F0E45689D0B40A] - 30/01/2015 - 10:20:29 ---A- . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\Drivers\mrxsmb20.sys [206848]
O44 - LFC:[MD5.83E7C4DA3BF4A21C3F809A506245CAEF] - 30/01/2015 - 10:20:29 ---A- . (.Microsoft Corporation - Media Foundation Proxy DLL.) -- C:\Windows\System32\mfps.dll [233888]
O44 - LFC:[MD5.B1AA3B19A2E596A59224F893E01A5A75] - 30/01/2015 - 10:20:29 ---A- . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) -- C:\Windows\System32\Drivers\NdisImPlatform.sys [126464]
O44 - LFC:[MD5.E4B4BE2D7750849C07589DA0B0AABA01] - 30/01/2015 - 10:20:29 ---A- . (.Microsoft Corporation - NDIS (Especificação de Interface de Driver.) -- C:\Windows\System32\Drivers\ndis.sys [1118040]
O44 - LFC:[MD5.504DDEF8526CECAAD886D5AC5656DF1A] - 30/01/2015 - 10:20:30 ---A- . (.Microsoft Corporation - Windows Cryptographic Primitives Library.) -- C:\Windows\System32\bcryptprimitives.dll [387896]
O44 - LFC:[MD5.02FE7859AD2DEAD7E9E3C7BF5F484204] - 30/01/2015 - 10:20:31 ---A- . (.Microsoft Corporation - Mixer de Volume.) -- C:\Windows\System32\SndVol.exe [211216]
O44 - LFC:[MD5.9A3AF816758D144B097AE477D99F7D79] - 30/01/2015 - 10:20:31 ---A- . (.Microsoft Corporation - Teclado Virtual para Acessibilidade.) -- C:\Windows\System32\osk.exe [834560]
O44 - LFC:[MD5.8EE8CA953542A8E70A841C453BC15196] - 30/01/2015 - 10:20:32 ---A- . (.Microsoft Corporation - Biblioteca API de Clusters.) -- C:\Windows\System32\clusapi.dll [427008]
O44 - LFC:[MD5.2C38FF9DE23A3BB335A95099622AB603] - 30/01/2015 - 10:20:32 ---A- . (.Microsoft Corporation - Extensão de Cliente de Política de Grupo de.) -- C:\Windows\System32\WorkFoldersGPExt.dll [65536]
O44 - LFC:[MD5.793DE7C6B82804D5973C43484F527849] - 30/01/2015 - 10:20:33 ---A- . (.Microsoft Corporation - Appx Subject Interface Package.) -- C:\Windows\System32\AppxSip.dll [117248]
O44 - LFC:[MD5.F8A869262251B011A21DEC79AC1F3F5D] - 30/01/2015 - 10:20:33 ---A- . (.Microsoft Corporation - Painel de Controle de Vídeo.) -- C:\Windows\System32\Display.dll [1844224]
O44 - LFC:[MD5.D62B6C0A254EADB94C138600E6DB6048] - 30/01/2015 - 10:20:33 ---A- . (.Microsoft Corporation - Windows Update Modern WuApp.) -- C:\Windows\System32\WUSettingsProvider.dll [388608]
O44 - LFC:[MD5.1C683FB45C6CE0BB8A74BB0B1392599D] - 30/01/2015 - 10:20:34 ---A- . (.Microsoft Corporation - Exibir Redes Disponíveis.) -- C:\Windows\System32\VAN.dll [505344]
O44 - LFC:[MD5.EA10272605422080EE2FAB142A75120D] - 30/01/2015 - 10:20:34 ---A- . (.Microsoft Corporation - Host da Janela do Console.) -- C:\Windows\System32\conhost.exe [356864]
O44 - LFC:[MD5.CD8CA57C36E596875865F451393C7C66] - 30/01/2015 - 10:20:34 ---A- . (.Microsoft Corporation - Setting Synchronization.) -- C:\Windows\System32\SettingSync.dll [576512]
O44 - LFC:[MD5.9D50C0B29FB20DF0A8FD197B332894B7] - 30/01/2015 - 10:20:35 ---A- . (.Microsoft Corporation - Base Multimedia Extension API DLL.) -- C:\Windows\System32\winmmbase.dll [160600]
O44 - LFC:[MD5.693CC2794DEFB8493ABFF68D509DACC4] - 30/01/2015 - 10:20:35 ---A- . (.Microsoft Corporation - DLL do Vídeo Wi-Fi.) -- C:\Windows\System32\WiFiDisplay.dll [127488]
O44 - LFC:[MD5.FEF0BC107812B36849741C3211BA6B60] - 30/01/2015 - 10:20:35 ---A- . (.Microsoft Corporation - Driver de Hub Padrão para USB.) -- C:\Windows\System32\Drivers\usbhub.sys [419648]
O44 - LFC:[MD5.618A19EB31ECA7B7F2AA0207BAF598A5] - 30/01/2015 - 10:20:35 ---A- . (.Microsoft Corporation - Enumerador de Dispositivos Portáteis.) -- C:\Windows\System32\wpdbusenum.dll [84480]
O44 - LFC:[MD5.26ACA481FAFEC59FE311D719E3027BBA] - 30/01/2015 - 10:20:36 ---A- . (.Microsoft Corporation - Driver da Miniporta NativeWiFi.) -- C:\Windows\System32\Drivers\nwifi.sys [446976]
O44 - LFC:[MD5.8DC2979BC54C585BA5A4C9E6FABCD1B4] - 30/01/2015 - 10:20:36 ---A- . (.Microsoft Corporation - Media Foundation ReadWrite DLL.) -- C:\Windows\System32\mfreadwrite.dll [360480]
O44 - LFC:[MD5.D047CD668E6277FD80F0C613946F034C] - 30/01/2015 - 10:20:36 ---A- . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\Drivers\srvnet.sys [246272]
O44 - LFC:[MD5.C80D4D7AF450F7CAD615FF1D7B40D7AD] - 30/01/2015 - 10:20:37 ---A- . (.Microsoft Corporation - Continuar a partir do aplicativo de inicial.) -- C:\Windows\System32\winresume.efi [1488008]
O44 - LFC:[MD5.3663F0BB881A16A689F33A21C1A3C76B] - 30/01/2015 - 10:20:37 ---A- . (.Microsoft Corporation - Continuar a partir do aplicativo de inicial.) -- C:\Windows\System32\winresume.exe [1356840]
O44 - LFC:[MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - 30/01/2015 - 10:20:37 ---A- . (.Microsoft Corporation - Driver de cópia de sombra de volume.) -- C:\Windows\System32\Drivers\volsnap.sys [310080]
O44 - LFC:[MD5.A4CF0D2FF18BF8D128389AF26410FD8B] - 30/01/2015 - 10:20:37 ---A- . (.Microsoft Corporation - Editor do descritor de segurança.) -- C:\Windows\System32\aclui.dll [1018368]
O44 - LFC:[MD5.FE7E47BE6E0D9EF4F24D81381A829CEC] - 30/01/2015 - 10:20:37 ---A- . (.Microsoft Corporation - Módulo de interface com o usuário do editor.) -- C:\Windows\System32\wsecedit.dll [1463808]
O44 - LFC:[MD5.D01BA613D268DAD03DD32A0DC5FD24DF] - 30/01/2015 - 10:20:38 ---A- . (.Microsoft Corporation - DLL do Monitor Padrão Dinâmico de Portas de.) -- C:\Windows\System32\usbmon.dll [287232]
O44 - LFC:[MD5.5B6B32E83E371739B13AA67E260DC5C4] - 30/01/2015 - 10:20:38 ---A- . (.Microsoft Corporation - Driver de spooler do Windows.) -- C:\Windows\System32\winspool.drv [487936]
O44 - LFC:[MD5.835261C17478103B73F4FFB8454AF849] - 30/01/2015 - 10:20:38 ---A- . (.Microsoft Corporation - Microsoft Pen and Touch Input Component.) -- C:\Windows\System32\wisp.dll [268288]
O44 - LFC:[MD5.D249C3A58A4FCF755EF4C94F7047E015] - 30/01/2015 - 10:20:38 ---A- . (.Microsoft Corporation - Microsoft\Otimizador de Unidade.) -- C:\Windows\System32\defragsvc.dll [449536]
O44 - LFC:[MD5.40CC457FB140B509B50F96DAD9D8F80B] - 30/01/2015 - 10:20:38 ---A- . (.Microsoft Corporation - OS Loader.) -- C:\Windows\System32\winload.efi [1660048]
O44 - LFC:[MD5.70696A95F26778CFCB106ECEAA40F4D9] - 30/01/2015 - 10:20:38 ---A- . (.Microsoft Corporation - OS Loader.) -- C:\Windows\System32\winload.exe [1519560]
O44 - LFC:[MD5.0FA02FD5BEF2B8FBA63B40746360E9C6] - 30/01/2015 - 10:20:39 ---A- . (.Microsoft Corporation - API do Cliente do Windows Update.) -- C:\Windows\System32\wuapi.dll [828416]
O44 - LFC:[MD5.D0AD65EE089F735BF546ABFE28D192C0] - 30/01/2015 - 10:20:39 ---A- . (.Microsoft Corporation - DLL de diálogos comuns.) -- C:\Windows\System32\comdlg32.dll [621056]
O44 - LFC:[MD5.C40DE04CE3A8905EB8048B5CE0951DF0] - 30/01/2015 - 10:20:39 ---A- . (.Microsoft Corporation - Media Foundation Platform DLL.) -- C:\Windows\System32\mfplat.dll [882136]
O44 - LFC:[MD5.FF1CB6C5D9288DAAA0DADAD6B1E35085] - 30/01/2015 - 10:20:39 ---A- . (.Microsoft Corporation - Media Foundation Transcode DLL.) -- C:\Windows\System32\mftranscode.dll [205512]
O44 - LFC:[MD5.240C5C3793206725AA05665851E8C214] - 30/01/2015 - 10:20:39 ---A- . (.Microsoft Corporation - Storage Spaces Driver.) -- C:\Windows\System32\Drivers\spaceport.sys [412992]
O44 - LFC:[MD5.3C120DEE84D42246A17A917B2B934A36] - 30/01/2015 - 10:20:40 ---A- . (...) -- C:\Windows\System32\locale.nls [513544]
O44 - LFC:[MD5.7740658736BD07FC121EACB3CA7C9194] - 30/01/2015 - 10:20:40 ---A- . (.Microsoft Corporation - WMI Provider for Storage Management.) -- C:\Windows\System32\storagewmi.dll [2397184]
O44 - LFC:[MD5.79EFAEE6FBD8ABC066B944E1A7A605BB] - 30/01/2015 - 10:20:41 ---A- . (.Microsoft Corporation - SHCORE.) -- C:\Windows\System32\SHCore.dll [645592]
O44 - LFC:[MD5.FF78D053A05E5A394F4E3C1816CC65A8] - 30/01/2015 - 10:20:41 ---A- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\Drivers\usbccgp.sys [143680]
O44 - LFC:[MD5.42FEA9E0BA9761D9E65A4F167D91515B] - 30/01/2015 - 10:20:42 ---A- . (.Microsoft Corporation - Aplicativo de subsistema de spooler.) -- C:\Windows\System32\spoolsv.exe [795136]
O44 - LFC:[MD5.793EACA6BAE9F481C2059BCB3743EB4A] - 30/01/2015 - 10:20:42 ---A- . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\Windows\System32\srvsvc.dll [324096]
O44 - LFC:[MD5.BF6897E960C08E9FDD41B80726C61C2F] - 30/01/2015 - 10:20:42 ---A- . (.Microsoft Corporation - Windows Wireless LAN 802.11 MSM DLL.) -- C:\Windows\System32\wlanmsm.dll [371200]
O44 - LFC:[MD5.0A7F97DE49DB63E01CBCA067F4DA7AB8] - 30/01/2015 - 10:20:43 ---A- . (.Microsoft Corporation - Biblioteca de Compactação de Appx de Código.) -- C:\Windows\System32\AppxPackaging.dll [544768]
O44 - LFC:[MD5.B2C26168E74EA51BF65518A309B08C19] - 30/01/2015 - 10:20:43 ---A- . (.Microsoft Corporation - Painel de Controle de Pastas de Trabalho da.) -- C:\Windows\System32\WorkfoldersControl.dll [770048]
O44 - LFC:[MD5.A9C015F01499761908DE61F172FAF65D] - 30/01/2015 - 10:20:44 ---A- . (.Microsoft Corporation - Objetos de configuração de rede.) -- C:\Windows\System32\netcfgx.dll [486744]
O44 - LFC:[MD5.4301A4D673F1ACB195C4F30B306B70B9] - 30/01/2015 - 10:20:44 ---A- . (.Microsoft Corporation - XPS Printing DLL.) -- C:\Windows\System32\XpsPrint.dll [1992192]
O44 - LFC:[MD5.5BED3AB69797C8786EF70AEA8C33748B] - 30/01/2015 - 10:20:45 ---A- . (.Microsoft Corporation - Driver de Servidor Smb 2.0.) -- C:\Windows\System32\Drivers\srv2.sys [674816]
O44 - LFC:[MD5.038C77D577900EE39410662478BB0D50] - 30/01/2015 - 10:20:46 ---A- . (.Microsoft Corporation - Driver do Sistema de Arquivos NT.) -- C:\Windows\System32\Drivers\ntfs.sys [2009920]
O44 - LFC:[MD5.17E700D2F6671196D0512BF806BB6435] - 30/01/2015 - 10:20:46 ---A- . (.Microsoft Corporation - Interface de Usuário das Configurações de I.) -- C:\Windows\System32\printui.dll [1182208]
O44 - LFC:[MD5.D24002EB2F4A8A04897703067E81CC5D] - 30/01/2015 - 10:20:46 ---A- . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [3465216]
O44 - LFC:[MD5.AEAD37FA03D6E90638D8A4DC30E50408] - 30/01/2015 - 10:20:47 ---A- . (.Microsoft Corporation - DLL do Auxiliar de Leitor de Tela.) -- C:\Windows\System32\SRH.dll [2050560]
O44 - LFC:[MD5.8200B4C323229AA1F47C87EB37207E36] - 30/01/2015 - 10:20:47 ---A- . (.Microsoft Corporation - Decodificador de Vídeo do Windows Media Vid.) -- C:\Windows\System32\WMVDECOD.DLL [2574208]
O44 - LFC:[MD5.6416E79A58A8FCC33A447A4DDDD3BF04] - 30/01/2015 - 10:20:48 ---A- . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\Drivers\srv.sys [412160]
O44 - LFC:[MD5.11FA35E24D76F62BD3E64D43B12656EF] - 30/01/2015 - 10:20:50 ---A- . (.Microsoft Corporation - Windows Media Runtime DLL.) -- C:\Windows\System32\Windows.Media.dll [1231872]
O44 - LFC:[MD5.61BF52E9FFAB27A0B6D621BE26088373] - 30/01/2015 - 10:20:51 ---A- . (.Microsoft Corporation - Serviço Pastas de Trabalho da Microsoft (C).) -- C:\Windows\System32\workfolderssvc.dll [1600000]
O44 - LFC:[MD5.69DB09F0263C637DA8568D404842466A] - 30/01/2015 - 10:20:52 ---A- . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [1261056]
O44 - LFC:[MD5.3F5EF31C6AA204B099EE76497DF80A26] - 30/01/2015 - 10:20:52 ---A- . (.Microsoft Corporation - DLL do Serviço de Configuração Automática d.) -- C:\Windows\System32\wlansvc.dll [1532416]
O44 - LFC:[MD5.AD3137A754F60D369C176EF4DD5084A0] - 30/01/2015 - 10:20:53 ---A- . (.Microsoft Corporation - Media Foundation Core DLL.) -- C:\Windows\System32\mfcore.dll [2141920]
O44 - LFC:[MD5.CC59B18DEC31120F9957ABA55EC49FAC] - 30/01/2015 - 10:20:58 ---A- . (.Microsoft Corporation - Direct3D 10 Rasterizer.) -- C:\Windows\System32\d3d10warp.dll [2389504]
O44 - LFC:[MD5.49EEC8569BF200C95A38D00766AFB830] - 30/01/2015 - 10:21:05 ---A- . (.Microsoft Corporation - Windows.UI.Xaml dll.) -- C:\Windows\System32\Windows.UI.Xaml.dll [16874496]
~ Files: 348 Scanned in 04mn 09s



---\\ Últimos arquivos criados no Windows Prefetcher (045)
O45 - LFCP:[MD5.B5BDBE64BFF8368FDEA2CE4372F1A0C6] - 26/01/2015 - 19:02:27 ---A- - C:\Windows\Prefetch\BITTORRENT.EXE-C841118E.pf =>P2P.BitTorrent
O45 - LFCP:[MD5.D7CE8B7988992866AF94FF35075B0AB4] - 05/02/2015 - 00:29:07 ---A- - C:\Windows\Prefetch\UTORRENT.EXE-29F4A1BA.pf =>P2P.µTorrent
O45 - LFCP:[MD5.31331DB31B24FEE6B38E2FC69EB7C16A] - 26/01/2015 - 19:01:11 ---A- - C:\Windows\Prefetch\UTORRENT.EXE-5F757592.pf =>P2P.µTorrent
O45 - LFCP:[MD5.CF6E5AC692D340A5E19C0B0D3137400E] - 04/02/2015 - 23:26:00 ---A- - C:\Windows\Prefetch\WPM_V20.0.0.1714_0204.EXE-838A75E8.pf =>PUP.WpManager
O45 - LFCP:[MD5.5B367AD9B6BC6F2D17D7F7C970E4CB99] - 04/02/2015 - 23:25:58 ---A- - C:\Windows\Prefetch\WPM_V20.0.0.1714_0204.EXE-8C976BD7.pf =>PUP.WpManager
~ Prefetcher: 5 Scanned in 00mn 01s



---\\ Negação do serviço (Local Security Authority) (048)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Mecanismo cliente do 'Editor de configuração de segurança Windows'.) -- C:\Windows\System32\scecli.dll
~ LSA: 3 Scanned in 00mn 00s



---\\ Controlo do Modo de Segurança (CSB) (49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Driver de porta de mouse serial.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Driver de Extensão do Gerenciador de Volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\mfefirek.sys . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\Windows\System32\Drivers\mfefirek.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\mfehidk.sys . (.McAfee, Inc. - McAfee Link Driver.) -- C:\Windows\System32\Drivers\mfehidk.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (...) -- C:\Windows\System32\Drivers\rdpencdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Driver de porta de mouse serial.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Driver de Extensão do Gerenciador de Volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 19 Scanned in 00mn 00s



---\\ Pesquisa de infeções nos drivers (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ TDSD: 2 Scanned in 00mn 01s



---\\ Enumeração das chaves do registo SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s



---\\ Enumeração das chaves do registo PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableCursorSuppression"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "DisableTaskMgr"=0
O55 - MWPS:[HKLM\...\Policies\System] - "DisableRegistryTools"=0
O55 - MWPS:[HKCU\...\Policies\System] - "DisableRegistryTools"=0
O55 - MWPS:[HKCU\...\Policies\System] - "DisableTaskMgr"=0
~ MWPS: 21 Scanned in 00mn 00s



---\\ Enumeração das chaves do registo PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoRun"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoFolderOptions"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoControlPanel"=0
~ MWPE Keys: 6 Scanned in 00mn 00s



---\\ Lista dos drivers do sistema (SDL) (O58)
O58 - SDL:22/08/2013 - 09:43:41 ---A- . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\Drivers\3ware.sys [108896]
O58 - SDL:22/08/2013 - 09:43:41 ---A- . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller.) -- C:\Windows\System32\Drivers\adp80xx.sys [782176]
O58 - SDL:22/08/2013 - 09:43:41 ---A- . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [79200]
O58 - SDL:22/08/2013 - 09:43:41 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [259424]
O58 - SDL:22/08/2013 - 09:43:40 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [25952]
O58 - SDL:22/08/2013 - 09:43:41 ---A- . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [114016]
O58 - SDL:06/12/2012 - 11:02:20 ---A- . (.AVerMedia TECHNOLOGIES, Inc. - AVerMedia Hybrid TV Driver.) -- C:\Windows\System32\Drivers\AVerPola.sys [744320]
O58 - SDL:06/12/2012 - 11:02:30 ---A- . (.AVerMedia TECHNOLOGIES, Inc. - AVerMedia USB Polaris Series DIR Driver.) -- C:\Windows\System32\Drivers\AVPolDIR.sys [7168]
O58 - SDL:12/08/2013 - 20:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624]
O58 - SDL:22/08/2013 - 09:43:41 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [531296]
O58 - SDL:20/06/2014 - 09:38:22 ---A- . (.McAfee, Inc. - McAfee Personal Firewall IDS Plugin.) -- C:\Windows\System32\Drivers\cfwids.sys [72128]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3357024]
O58 - SDL:06/06/2012 - 23:26:42 ---A- . (.Fintek - Fintek Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\FintekCIR.sys [33128]
O58 - SDL:01/07/2012 - 23:16:02 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECIx64.sys [62784]
O58 - SDL:23/09/2013 - 12:49:22 ---A- . (.McAfee, Inc. - McAfee HIP IPS Driver.) -- C:\Windows\System32\Drivers\HipShieldK.sys [197704]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [64352]
O58 - SDL:30/07/2013 - 15:47:35 ---A- . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\Drivers\iaLPSSi_GPIO.sys [24568]
O58 - SDL:25/07/2013 - 16:05:39 ---A- . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\Drivers\iaLPSSi_I2C.sys [99320]
O58 - SDL:09/07/2012 - 13:43:12 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\Windows\System32\Drivers\iaStorA.sys [645952]
O58 - SDL:09/08/2013 - 21:39:30 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver (inbox) - x64.) -- C:\Windows\System32\Drivers\iaStorAV.sys [651248]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [412000]
O58 - SDL:01/10/2014 - 18:54:16 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd64.sys [3828152]
O58 - SDL:19/06/2012 - 07:40:50 ---A- . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\Drivers\IntcDAud.sys [342528]
O58 - SDL:01/08/2014 - 17:18:33 ---A- . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\Drivers\intelaud.sys [38296]
O58 - SDL:01/08/2014 - 17:18:33 ---A- . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\Drivers\iwdbus.sys [27032]
O58 - SDL:22/08/2013 - 09:43:44 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [109408]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [93536]
O58 - SDL:22/08/2013 - 09:43:44 ---A- . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas3.sys [81760]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sss.sys [82784]
O58 - SDL:21/11/2014 - 05:14:08 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [25816]
O58 - SDL:21/11/2014 - 05:14:12 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [93400]
O58 - SDL:29/01/2015 - 10:40:15 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [129752]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\Drivers\megasas.sys [56672]
O58 - SDL:22/08/2013 - 09:43:45 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\megasr.sys [575840]
O58 - SDL:20/06/2014 - 09:20:54 ---A- . (.McAfee, Inc. - Access Protection Filter Driver.) -- C:\Windows\System32\Drivers\mfeapfk.sys [181704]
O58 - SDL:20/06/2014 - 09:21:48 ---A- . (.McAfee, Inc. - Anti-Virus File System Filter Driver.) -- C:\Windows\System32\Drivers\mfeavfk.sys [313544]
O58 - SDL:20/08/2014 - 07:07:00 ---A- . (.McAfee, Inc. - McAfee Driver Cleaning Driver.) -- C:\Windows\System32\Drivers\mfeclnrk.sys [11336]
O58 - SDL:20/06/2014 - 09:09:34 ---A- . (.McAfee, Inc. - McAfee ELAM Driver.) -- C:\Windows\System32\Drivers\mfeelamk.sys [70600]
O58 - SDL:20/06/2014 - 09:23:40 ---A- . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\Windows\System32\Drivers\mfefirek.sys [523792]
O58 - SDL:20/06/2014 - 09:26:02 ---A- . (.McAfee, Inc. - McAfee Link Driver.) -- C:\Windows\System32\Drivers\mfehidk.sys [786296]
O58 - SDL:20/08/2014 - 07:05:28 ---A- . (.McAfee, Inc. - Event Driver.) -- C:\Windows\System32\Drivers\mfencbdc.sys [445512]
O58 - SDL:20/08/2014 - 07:06:14 ---A- . (.McAfee, Inc. - Detection driver.) -- C:\Windows\System32\Drivers\mfencrk.sys [96592]
O58 - SDL:20/06/2014 - 09:31:06 ---A- . (.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) -- C:\Windows\System32\Drivers\mfewfpk.sys [348552]
O58 - SDL:22/08/2013 - 09:43:49 ---A- . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\Drivers\mvumis.sys [63840]
O58 - SDL:21/11/2014 - 05:14:26 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [64216]
O58 - SDL:22/08/2013 - 09:43:31 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [150368]
O58 - SDL:22/08/2013 - 09:43:32 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [168288]
O58 - SDL:31/07/2012 - 00:04:12 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Driver.) -- C:\Windows\System32\Drivers\Rt630x64.sys [690832]
O58 - SDL:05/06/2013 - 19:39:48 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [3443656]
O58 - SDL:12/03/2013 - 18:39:44 ---A- . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driverr.) -- C:\Windows\System32\Drivers\rtwlane.sys [1544704]
O58 - SDL:22/08/2013 - 12:35:09 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040]
O58 - SDL:22/08/2013 - 09:43:31 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [44896]
O58 - SDL:22/08/2013 - 09:43:32 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [81760]
O58 - SDL:22/08/2013 - 09:43:32 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072]
O58 - SDL:12/11/2010 - 14:31:04 ---A- . (...) -- C:\Windows\System32\Drivers\UCORESYS.sys [14632]
O58 - SDL:22/08/2013 - 09:43:34 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [19808]
O58 - SDL:22/08/2013 - 09:43:34 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [168800]
O58 - SDL:22/08/2013 - 09:43:34 ---A- . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\Drivers\VSTXRAID.SYS [305504]
~ Drivers: 58 Scanned in 00mn 05s



---\\ Últimos ficheiros alterados ou criados (Utilizador) (061)
O61 - LFC: 04/02/2015 - 01:39:52 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Microsoft\Windows\INetCache\IE\EK95YZKK\XTab_4.0.2.1716[1].exe [2463400]
O61 - LFC: 04/02/2015 - 01:40:01 ---A- . (.Install Setup App.) -- C:\Users\IGOR\AppData\Local\Temp\n2136\s2136.exe [290896]
O61 - LFC: 05/02/2015 - 01:39:48 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [200]
O61 - LFC: 05/02/2015 - 01:40:07 ---A- . (.Nicolas Coolman.) -- C:\Users\IGOR\Downloads\ZHPDiag2 (1).exe [6870007] =>.Nicolas Coolman
O61 - LFC: 29/01/2015 - 01:40:07 ---A- . (.Nicolas Coolman.) -- C:\Users\IGOR\Downloads\ZHPDiag2.exe [6869662] =>.Nicolas Coolman
O61 - LFC: 29/01/2015 - 01:40:07 ---A- . (.Thisisu.) -- C:\Users\IGOR\Downloads\JRT.exe [1707939]
O61 - LFC: 30/01/2015 - 01:39:55 ---A- . (.AdDuplex.) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\AdDuplex.Controls\4174803412489daaffaf80744e02ebf4\AdDuplex.Controls.ni.dll [284160]
O61 - LFC: 30/01/2015 - 01:39:55 ---A- . (.AdDuplex.) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\AdDuplex.WinRT\e27aa368f964520f429c1911d25052a2\AdDuplex.WinRT.ni.dll [513024]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.127106e4#\3a2b55f31a82daa48be878cd0cdff98a\Archivator.ViewModels.Windows.ni.dll [393216]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.Helpers\9f9035e61b4f0c13b8d6fb12fdd709d1\Archivator.Helpers.ni.dll [173568]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.Models\54082defea0965e833867256306b400a\Archivator.Models.ni.dll [98304]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.Resources\511626d95a008744ef4ee5f428a6e63e\Archivator.Resources.ni.dll [46592]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.Windows\c133a21c274d9ed53a812410295f6aec\Archivator.Windows.ni.exe [451072]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.e830cafb#\021746961f243a3dc7cd2652d6bb70fd\Archivator.PlatformSpecific.ni.dll [241664]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Archivator.eacf9470#\db6e673dd462917ff433a94d3a58ce67\Archivator.DataAccess.ni.dll [137216]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Banner.WindowsStore\6273b162d59b989c7c60b4e7ce8c80c8\Banner.WindowsStore.ni.dll [370688]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\CommonToolk4a639370#\87daeb69cc428668e5c43386b0612d84\CommonToolkit.Core.Universal.ni.dll [651264]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\CommonToolkc2d7f594#\21af209f292f6537a3afdea1892bb18a\CommonToolkit.Core.Shared.ni.dll [1053184]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\CommonToolkf328f1bf#\5b9a51f06e67a5cf427e5b89227c2117\CommonToolkit.Controls.Universal.ni.dll [608256]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\GoogleAnalytics.Core\5e12632e6c43754d7d964e435b238b9d\GoogleAnalytics.Core.ni.dll [507392]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\GoogleAnalytics\a6f07e4e44e25a80a10ba6b1ab741c0c\GoogleAnalytics.ni.dll [256512]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\MessageServd88aaa82#\bdecd5b97af0d78c6769f23ce17958af\MessageServiceLibrary.WindowsStore.ni.dll [161792]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.W64cef312#\3de779d44403337b94b0eff72e165c09\Microsoft.WindowsAzure.Messaging.Managed.ni.dll [901632]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (.GalaSoft Laurent Bugnion @ <a href="'http://www.galas/'" target="_blank">http://www.galas</a>.) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\GalaSoft.Mv591a4917#\b58f466c1fea5bd688348cf400c26fe8\GalaSoft.MvvmLight.Extras.ni.dll [95744]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (.GalaSoft Laurent Bugnion @ <a href="'http://www.galas/'" target="_blank">http://www.galas</a>.) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\GalaSoft.MvvmLight\b38ac1b649f52f122a0e2e3eb6948b29\GalaSoft.MvvmLight.ni.dll [209920]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (.Microsoft.) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.P4d3ce419#\107c6690ec3b1474b697cc041351cabf\Microsoft.Practices.ServiceLocation.ni.dll [35328]
O61 - LFC: 30/01/2015 - 01:39:56 ---A- . (.Tim Heuer.) -- C:\Users\IGOR\AppData\Local\Packages\9FD20106.ExtractorforZIPandRAR_nwhm06f2kfry2\AC\Microsoft\CLR_v4.0\NativeImages\Callisto\b68b8d2c8415fabcb14ce9c5f1b2b94a\Callisto.ni.dll [740352]
O61 - LFC: 30/01/2015 - 01:39:57 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.PerfTrack\10ead687afca927bd7b22ad8d20e1de3\Microsoft.PerfTrack.ni.dll [28160]
O61 - LFC: 30/01/2015 - 01:39:57 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\SqliteWrapper\99fa190c50aa9d06da5fb90ed0d8b8f7\SqliteWrapper.ni.dll [117248]
O61 - LFC: 30/01/2015 - 01:39:57 ---A- . (.Microsoft.) -- C:\Users\IGOR\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Platform\41b50690fab51a65b808832ac9a9e827\Platform.ni.dll [6372864]
O61 - LFC: 30/01/2015 - 01:40:07 ---A- . (.Banco Itaú.) -- C:\Users\IGOR\Downloads\DiagnosticoItau.exe [3190840]
O61 - LFC: 31/01/2015 - 01:39:49 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\urlblocklist.bin [0]
O61 - LFC: 31/01/2015 - 01:39:51 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Microsoft\Windows\INetCache\IE\EJEAUJTD\urlblockindex[1].bin [16]
O61 - LFC: 31/01/2015 - 01:39:55 ---A- . (...) -- C:\Users\IGOR\AppData\Local\Microsoft\Windows\INetCache\IE\LQ0A66ND\urlblocklist[1].bin [0]
O61 - LFC: 31/01/2015 - 01:40:07 ---A- . (...) -- C:\Users\IGOR\Downloads\AdsFix.exe [2453504]
~ 57 Fichiers temporaires (Temporary files)
~ Files: 35 Scanned in 00mn 20s



---\\ Lista das ferramentas de remoção de vírus (LAT) (063)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associações Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Iniciador do snap-in de 'Visualizar eventos'.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Scanned in 00mn 00s



---\\ Menu de inicialização Internet (068)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Pesquisa de infeção nos navegadores da Internet (SBI) (069)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} [DefaultScope] - (e) - <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (omiga-plus) - <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {E733165D-CBCF-4FDA-883E-ADEF965B476C} - (Google) - <a href="'http://isearch.omiga-plus.com/'" target="_blank">http://isearch.omiga-plus.com</a> =>Hijacker.OmigaPlus
~ Keys: Scanned in 00mn 00s



---\\ Listagem dos ficheiros Crack & Keygen (CKF) (O82)
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\basic_people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\client_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\lang_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\non_pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\non_pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\non_pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\server_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\basic_people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\client_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\lang_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\non_pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\non_pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\non_pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\server_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\summary.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.1500.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.1756.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.2424.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.2872.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.3308.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.4612.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe.4892.STEAMSTART =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\helper.exe =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\icudtl.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\<a href="'http://www.3dmgame.com.url/'" target="_blank">www.3dmgame.com.url</a> =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\_CommonRedist\DirectX\dxwebsetup.exe =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\<a href="'http://www.3dmgame.com.url/'" target="_blank">www.3dmgame.com.url</a> =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\basic_people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\client_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\lang_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\non_pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\non_pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\non_pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fm\server_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\basic_people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\client_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\lang_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\non_pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\non_pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\non_pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\people_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\pl_hist_dt.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\pl_hist_id.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\pl_hist_index.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\db\1500\1500_fmc\server_db.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\data\summary.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\fm.exe =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\helper.exe =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\icudtl.dat =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\<a href="'http://www.3dmgame.com.url/'" target="_blank">www.3dmgame.com.url</a> =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\Football Manager 2015\_CommonRedist\DirectX\dxwebsetup.exe =>.Crack,Keygen
C:\Users\IGOR\Downloads\3DMGAME-Football.Manager.2015.v15.1.3.Cracked-3DM\<a href="'http://www.3dmgame.com.url/'" target="_blank">www.3dmgame.com.url</a> =>.Crack,Keygen
C:\Users\IGOR\Downloads\football.manager.2015.v15.1.3.cracked-3dm.exe =>.Crack,Keygen
~ Files: Scanned in 00mn 31s



---\\ Listagem dos serviços iniciados pelo Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Serviço de Experiência com Aplicativo.) -- C:\Windows\System32\aelupsvc.dll [208896]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Cartão Inteligente da Microsof.) -- C:\Windows\System32\certprop.dll [155136]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Serviço de Propagação de Certificado de Cartão Inteligente da Microsof.) -- C:\Windows\System32\certprop.dll [155136]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL de Serviço do Servidor.) -- C:\Windows\System32\srvsvc.dll [324096]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Cliente da Política de Grupo.) -- C:\Windows\System32\gpsvc.dll [1261056]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extensão IKE.) -- C:\Windows\System32\ikeext.dll [1063424]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Serviço que oferece conectividade IPv6 em uma rede IPv4..) -- C:\Windows\System32\iphlpsvc.dll [914432]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\Windows\system32\seclogon.dll [30720]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Serviço de Informações de Aplicativos.) -- C:\Windows\System32\appinfo.dll [110080]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Serviço de Descoberta iSCSI.) -- C:\Windows\System32\iscsiexe.dll [150528]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Serviço Microsoft EAPHost.) -- C:\Windows\System32\eapsvc.dll [107008]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Serviço Agendador de Tarefas.) -- C:\Windows\System32\schedsvc.dll [1212928]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [220672]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Serviço Agendador de Classes de Multimídia.) -- C:\Windows\System32\mmcss.dll [70656]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL de Serviço Pesquisador de Computadores.) -- C:\Windows\System32\browser.dll [134144]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [225280]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Serviço de Configuração da Área de Trabalho Remota.) -- C:\Windows\System32\sessenv.dll [324096]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Relatórios de Problemas e Soluções.) -- C:\Windows\System32\wercplsupport.dll [81408]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\Windows\System32\kmsvc.dll [97792]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Serviço BDE.) -- C:\Windows\System32\bdesvc.dll [339456]
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Serviço de Estrutura de Localização do Windows.) -- C:\Windows\System32\GeofenceMonitorService.dll [491520]
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Serviço Conta da Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1576960]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL do Serviço de Tema do Shell do Windows.) -- C:\Windows\System32\themeservice.dll [50688]
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gerenciador de Instalação de Dispositivo.) -- C:\Windows\System32\DeviceSetupManager.dll [201728]
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Serviço Assistente de Conectividade de Rede da Microsoft.) -- C:\Windows\System32\ncasvc.dll [164352]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gerenciador de Discagem Automática de Acesso Remoto.) -- C:\Windows\System32\rasauto.dll [101376]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gerenciador de conexão de acesso remoto.) -- C:\Windows\System32\rasmans.dll [534528]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gerenciador de Interface Dinâmica.) -- C:\Windows\System32\mprdim.dll [223744]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Serviço de Notificação de Eventos do Sistema (SENS).) -- C:\Windows\System32\sens.dll [71680]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\Windows\System32\ipnathlp.dll [433664]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft(R) Windows(TM).) -- C:\Windows\System32\tapisrv.dll [306688]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [3465216]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de tela de fundo.) -- C:\Windows\System32\qmgr.dll [1017856]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\Windows\System32\shsvcs.dll [629760]
~ Services: 34 Scanned in 00mn 01s



---\\ Lista das exceções do FireWall (FirewallRules) (O87)
O87 - FAEL: "{12958694-5132-4AEE-AF3C-55956537743A}" | In - None - P6 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O87 - FAEL: "{63B40015-4C7C-406B-96F8-D5218645563E}" | In - None - P17 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
~ Firewall: 2 Scanned in 00mn 02s



---\\ Listagem dos dados da chave NameSpace (MNS) (O92)
O92 - MNS: - {1CF1260C-4DD0-4ebb-811F-33C572699FDE}
O92 - MNS: - {374DE290-123F-4565-9164-39C4925E467B}
O92 - MNS: - {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}
O92 - MNS: - {A0953C92-50DC-43bf-BE83-3742FED03C9C}
O92 - MNS: - {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}
O92 - MNS: - {B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
~ MNS: 6 Scanned in 00mn 00s



---\\ Estado general dos serviços não Microsoft (EGS) (SR=Executados, SS=Parados)
SS - | Demand 01/10/2014 281488 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe
SS - | Auto 26/01/2015 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 26/01/2015 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 24/07/2013 334608 | (McAWFwk) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe
SS - | Demand 08/10/2014 603424 | (McODS) . (.McAfee, Inc..) - C:\Program Files\mcafee\VirusScan\mcods.exe
SS - | Disabled 30/07/2013 328928 | (McOobeSv2) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
SS - | Auto 02/01/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SR - | Auto 26/06/2013 368640 | (AVerRemote) . (.AVerMedia.) - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
SR - | Auto 01/04/2011 403456 | (AVerScheduleService) . (...) - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
SR - | Auto 31/10/2011 167936 | (AVerUpdateServer) . (.AVerMedia TECHNOLOGIES, Inc..) - C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe
SR - | Auto 30/07/2013 328928 | (HomeNetSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
SR - | Auto 09/07/2012 7168 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 01/10/2014 319376 | (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe
SR - | Auto 16/01/2015 158896 | (IHProtect Service) . (.XTab system.) - C:\Program Files (x86)\XTab\ProtectService.exe =>Adware.AgentODR
SR - | Auto 20/04/2012 635104 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
SR - | Auto 17/07/2012 128896 | (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
SR - | Auto 17/07/2012 165760 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
SR - | Auto 17/07/2012 276864 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 03/12/2014 154320 | (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
SR - | Auto 25/04/2014 178528 | (McAPExe) . (.McAfee, Inc..) - C:\Program Files\McAfee\MSC\McAPexe.exe
SR - | Auto 30/07/2013 328928 | (McMPFSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
SR - | Auto 30/07/2013 328928 | (McNaiAnn) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
SR - | Auto 30/07/2013 328928 | (mcpltsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
SR - | Auto 30/07/2013 328928 | (McProxy) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
SR - | Auto 20/08/2014 1041192 | (mfecore) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
SR - | Auto 20/06/2014 219752 | (mfefire) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
SR - | Auto 20/06/2014 189912 | (mfevtp) . (.McAfee, Inc..) - C:\Windows\system32\mfevtps.exe
SR - | Auto 30/07/2013 328928 | (MSK80Service) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
SR - | Auto 17/07/2012 364416 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Demand 22/07/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe
SR - | Demand 22/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe
SR - | Auto 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Demand 22/08/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 19s



---\\ Pesquisa de infeção no Registo Mestre de Inicialização (MBR) (080)
Run by IGOR at 05/02/2015 01:42:56
~ OS 64 not supported by MBR tool
~ MBR: 0 Scanned in 00mn 00s



---\\ Pesquisa de infeção no Registo Mestre de Inicialização (MBRCheck) (080)
Written by ad13, <a href="'http://ad13.geekstog/'" target="_blank">http://ad13.geekstog</a>
Run by IGOR at 05/02/2015 01:42:58
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s



---\\ Scâner Aditional (088)
Database Version : 13008 - (02/02/2015)
Clés trouvées (Keys found) : 5
Valeurs trouvées (Values found) : 8
Dossiers trouvés (Folders found) : 4
Fichiers trouvés (Files found) : 8

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}] =>PUP.SupTab^
[HKLM\SYSTEM\CurrentControlSet\Services\IHProtect Service] =>Adware.AgentODR^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent] =>P2P.BitTorrent^
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:uTorrent =>P2P.BitTorrent^
C:\ProgramData\IHProtectUpDate =>Adware.AgentODR^
C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu^
C:\Users\IGOR\AppData\Roaming\BitTorrent =>P2P.BitTorrent^
C:\Users\IGOR\AppData\Roaming\uTorrent =>P2P.µTorrent^
C:\Program Files (x86)\XTab\cmdshell.exe =>PUP.SearchProtect^
C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent^
[HKCU\Software\BitTorrent] =>P2P.BitTorrent^
[HKLM\Software\Wow6432Node\IHProtect] =>Adware.AgentODR^
[HKLM\Software\Wow6432Node\SupDp] =>PUP.SupTab^
[HKLM\Software\Wow6432Node\omiga-plusSoftware] =>Hijacker.OmigaPlus^
[HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab^
[HKLM\Software\Wow6432Node\supWindowsMangerProtect] =>PUP.Fuyu^
~ Additionnel Scan: 177485 Items scanned in 00mn 30s



---\\ Informações complémentaires do módulos
~ <a href="http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/" target="_blank">http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/</a> =>.Internet Explorer, Gestão do Proxy (R5)
~ <a href="http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/" target="_blank">http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/</a> =>.Browser Helper Objects do navegador (02)
~ <a href="http://nicolascoolman.fr/o3-internet-explorer-toolbars/" target="_blank">http://nicolascoolman.fr/o3-internet-explorer-toolbars/</a> =>.Barras do Internet Explorer (03))
~ <a href="http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/" target="_blank">http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/</a> =>.Aplicações iniciadas por registo & pastas (04)
~ AMI: 4 Scanned in 00mn 00s



---\\ Sumário das deteções encontradas na sua estação
<a href="http://nicolascoolman.fr/pup-searchprotect" target="_blank">http://nicolascoolman.fr/pup-searchprotect</a> =>PUP.SearchProtect
<a href="http://nicolascoolman.fr/hijacker-omigaplus" target="_blank">http://nicolascoolman.fr/hijacker-omigaplus</a> =>Hijacker.OmigaPlus
<a href="http://nicolascoolman.fr/pup-suptab" target="_blank">http://nicolascoolman.fr/pup-suptab</a> =>PUP.SupTab
<a href="http://www.nicolascoolman.fr/blog/" target="_blank">http://www.nicolascoolman.fr/blog/</a> =>Adware.AgentODR
<a href="http://www.nicolascoolman.fr/blog/" target="_blank">http://www.nicolascoolman.fr/blog/</a> =>PUP.Fuyu
<a href="http://nicolascoolman.fr/pup-wpmanager" target="_blank">http://nicolascoolman.fr/pup-wpmanager</a> =>PUP.WpManager
<a href="http://nicolascoolman.fr/pup-v9software" target="_blank">http://nicolascoolman.fr/pup-v9software</a> =>PUP.V9Software
~ MSI: 7 link(s) detected in 00mn 00s



End of the scan (1448 lines in 09mn 36s)(66.6)
caedurodrigues
caedurodrigu... Tô em todas Registrado
710 Mensagens 257 Curtidas
#4 Por caedurodrigu...
05/02/2015 - 14:36
Boa tarde PEDRAZZI,

  • Execute este script na ferramenta ZHPFix.
  • Copie estas informações que estão em vermelho para o Bloco de notas.
  • Com o Bloco de notas aberto, faça: ctrl+a >> ctrl+c.
  • À seguir, minimize o Bloco de notas.

Script ZHPFix
SysRestore
[MD5.77590CE0CDEB6BBEE8DC056FEA0B107C] - (.SearchProtect - CmdShell.exe.) -- C:\Program Files (x86)\XTab\cmdshell.exe [48304] [PID.1056] =>PUP.SearchProtect
[MD5.C04D8BC933470B3913E4E3E6C3115793] - (.XTab system - SupHPNot.exe.) -- C:\Program Files (x86)\XTab\HPNotify.exe [673968] [PID.4752]
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O2 - BHO: IETabPage Class [64Bits] - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} . (.Thinknice Co. Limited - SupTab setup package.) -- C:\Program Files (x86)\XTab\SupTab.dll =>PUP.SupTab
O4 - GS\QuickLaunch [IGOR]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exehttp://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O4 - GS\QuickLaunch [IGOR]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O4 - GS\TaskBar [IGOR]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exehttp://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O4 - GS\TaskBar [IGOR]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exehttp://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O4 - GS\Program [IGOR]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exehttp://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O4 - GS\Desktop [IGOR]: Igor - Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exehttp://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O23 - Service: IHProtect Service (IHProtect Service) . (.XTab system - ProtectSvc.exe.) - C:\Program Files (x86)\XTab\ProtectService.exe =>Adware.AgentODR
[HKLM\Software\Wow6432Node\IHProtect] =>Adware.AgentODR
[HKLM\Software\Wow6432Node\SupDp] =>PUP.SupTab
[HKLM\Software\Wow6432Node\omiga-plusSoftware] =>Hijacker.OmigaPlus
[HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab
[HKLM\Software\Wow6432Node\supWindowsMangerProtect] =>PUP.Fuyu
O43 - CFD: 05/02/2015 - 00:26:33 - [] ----D C:\ProgramData\IHProtectUpDate =>Adware.AgentODR
O43 - CFD: 05/02/2015 - 00:25:50 - [] ----D C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu
O45 - LFCP:[MD5.CF6E5AC692D340A5E19C0B0D3137400E] - 04/02/2015 - 23:26:00 ---A- - C:\Windows\Prefetch\WPM_V20.0.0.1714_0204.EXE-838A75E8.pf =>PUP.WpManager
O45 - LFCP:[MD5.5B367AD9B6BC6F2D17D7F7C970E4CB99] - 04/02/2015 - 23:25:58 ---A- - C:\Windows\Prefetch\WPM_V20.0.0.1714_0204.EXE-8C976BD7.pf =>PUP.WpManager
O61 - LFC: 04/02/2015 - 01:40:01 ---A- . (.Install Setup App.) -- C:\Users\IGOR\AppData\Local\Temp\n2136\s2136.exe [290896]
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} [DefaultScope] - (e) - http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (omiga-plus) - http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
O69 - SBI: SearchScopes [HKCU] {E733165D-CBCF-4FDA-883E-ADEF965B476C} - (Google) - http://isearch.omiga-plus.com =>Hijacker.OmigaPlus
SR - | Auto 16/01/2015 158896 | (IHProtect Service) . (.XTab system.) - C:\Program Files (x86)\XTab\ProtectService.exe =>Adware.AgentODR
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}] =>PUP.SupTab^
[HKLM\SYSTEM\CurrentControlSet\Services\IHProtect Service] =>Adware.AgentODR^
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
C:\ProgramData\IHProtectUpDate =>Adware.AgentODR^
C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu^
C:\Program Files (x86)\XTab\cmdshell.exe =>PUP.SearchProtect^
[HKLM\Software\Wow6432Node\IHProtect] =>Adware.AgentODR^
[HKLM\Software\Wow6432Node\SupDp] =>PUP.SupTab^
[HKLM\Software\Wow6432Node\omiga-plusSoftware] =>Hijacker.OmigaPlus^
[HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab^
[HKLM\Software\Wow6432Node\supWindowsMangerProtect] =>PUP.Fuyu^
ServiceStop:IHProtect Service
EmptyClsid
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
ShortcutFix


Abra a ferramenta ZHPFix. <d2512a7bebda302928ef9e5bd9206047>
Clique em IMPORTAÇÃO > OK
Clique "GO".
Poste o Relatório!


Um grande abraço.

bda2ffa2e92f7f2a44c02bfd0ae2986b
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos irreparáveis aos mesmos! >
PEDRAZZI
PEDRAZZI Novo Membro Registrado
30 Mensagens 0 Curtidas
#5 Por PEDRAZZI
05/02/2015 - 14:43

Rapport de ZHPFix 2015.1.15.1 par Nicolas Coolman, Update du 15/01/2015
Fichier d'export Registre :
Run by IGOR at 05/02/2015 14:42:33
High Elevated Privileges : OK
Windows 8 Home Premium Edition, 64-bit Service Pack 1 (9600)

Reciclagem vazia (00mn 05s)
Prefetcher vazio
Reparação de atalhos do navegador

========== Processo memória ==========
ELIMINÉ: Memory Process: C:\Program Files (x86)\XTab\cmdshell.exe

========== Estado dos serviços ==========
IHProtect Service Parado

========== Chaves do Registo ==========
ELIMINÉ: CLSID BHO: {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
ELIMINÉ: Service: IHProtect Service
ELIMINÉ: HKLM\Software\Wow6432Node\IHProtect
ELIMINÉ: HKLM\Software\Wow6432Node\SupDp
ELIMINÉ: HKLM\Software\Wow6432Node\omiga-plusSoftware
ELIMINÉ: HKLM\Software\Wow6432Node\supTab
ELIMINÉ: HKLM\Software\Wow6432Node\supWindowsMangerProtect
ELIMINÉ: SearchScopes :{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
ELIMINÉ: SearchScopes :{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
ELIMINÉ: SearchScopes :{33BB0A4E-99AF-4226-BDF6-49120163DE86}
ELIMINÉ: SearchScopes :{E733165D-CBCF-4FDA-883E-ADEF965B476C}
ELIMINÉ: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}

========== Valores do Registo ==========
Ausente Valor Perfil Padrão: FirewallRaz :
Ausente Valor Perfil Domínio FirewallRaz :
ELIMINÉ: FirewallRaz (Domain) : {9E3D57FC-7C37-4424-9352-4831E97D029D}
ELIMINÉ: FirewallRaz (Domain) : {548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}

========== Elementos dos dados do Registo ==========
ELIMINÉ: R0 - Main,Start Page = KCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
ELIMINÉ: R0 - Main,Start Page = KLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
ELIMINÉ: R0 - Main,Start Page = KLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page
ELIMINÉ: R1 Search Page = <a href="http://isearch.omiga-plus.com/web/?type=ds&ts=1423103138&from=key7&uid=TOSHIBAXMQ01ABF050_24S4CPTHTXX24S4CPTHT&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=ds&ts=1423103138&from=key7&uid=TOSHIBAXMQ01ABF050_24S4CPTHTXX24S4CPTHT&q={searchTerms}</a>
ELIMINÉ: R1 Search Page = <a href="http://isearch.omiga-plus.com/?type=hp&ts=1423103138&from=key7&uid=TOSHIBAXMQ01ABF050_24S4CPTHTXX24S4CPTHT" target="_blank">http://isearch.omiga-plus.com/?type=hp&ts=1423103138&from=key7&uid=TOSHIBAXMQ01ABF050_24S4CPTHTXX24S4CPTHT</a>
ELIMINÉ: R1 Search Page = <a href="http://isearch.omiga-plus.com/web/?type=ds&ts=1423103134&from=key7&uid=TOSHIBAXMQ01ABF050_24S4CPTHTXX24S4CPTHT&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=ds&ts=1423103134&from=key7&uid=TOSHIBAXMQ01ABF050_24S4CPTHTXX24S4CPTHT&q={searchTerms}</a>
ELIMINÉ: StartMenuInternet: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" <a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a>

========== Pastas ==========
Nenhuma pasta CLSID local utilizador vazia
ELIMINÉ Temporários windows (10)
ELIMINÉ Flash Cookies (0)

========== Ficheiros ==========
ELIMINÉ: c:\program files (x86)\xtab\suptab.dll
ELIMINÉ: c:\users\igor\appdata\roaming\microsoft\internet explorer\quick launch\google chrome.lnk (<a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a&gt
CRIADO: C:\Users\IGOR\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
ELIMINÉ: c:\users\igor\appdata\roaming\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk (<a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a&gt
CRIADO: C:\Users\IGOR\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
ELIMINÉ: c:\users\igor\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk (<a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a&gt
CRIADO: C:\Users\IGOR\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
ELIMINÉ: c:\users\igor\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\internet explorer.lnk (<a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a&gt
CRIADO: C:\Users\IGOR\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
ELIMINÉ: c:\users\igor\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnk (<a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a&gt
CRIADO: C:\Users\IGOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
ELIMINÉ: c:\users\igor\desktop\igor - chrome.lnk (<a href="http://isearch.omiga-plus.com" target="_blank">http://isearch.omiga-plus.com</a&gt
CRIADO: C:\Users\IGOR\Desktop\Igor - Chrome.lnk
ELIMINA REINICIAR: c:\program files (x86)\xtab\protectservice.exe
ELIMINÉ: c:\windows\prefetch\wpm_v20.0.0.1714_0204.exe-838a75e8.pf
ELIMINÉ: c:\windows\prefetch\wpm_v20.0.0.1714_0204.exe-8c976bd7.pf
ELIMINÉ: c:\users\igor\appdata\local\temp\n2136\s2136.exe
ELIMINÉ Temporários windows (56) (1.869.579 octets)
ELIMINÉ Flash Cookies (0) (0 octets)

========== Restauração Sistema ==========
Ponto de restauro do sistema criado com sucesso


========== Recapitulativo ==========
1 : Processo memória
12 : Chaves do Registo
4 : Valores do Registo
7 : Elementos dos dados do Registo
3 : Pastas
19 : Ficheiros
1 : Estado dos serviços
1 : Restauração Sistema


End of clean in 01mn 53s

========== Caminho do ficheiro do relatório ==========
C:\Users\IGOR\AppData\Roaming\ZHP\ZHPFix[R1].txt - 31/01/2015 14:35:33 [5266]
C:\Users\IGOR\AppData\Roaming\ZHP\ZHPFix[R2].txt - 05/02/2015 14:42:44 [4893]
caedurodrigues
caedurodrigu... Tô em todas Registrado
710 Mensagens 257 Curtidas
#6 Por caedurodrigu...
05/02/2015 - 15:34
Boa tarde PEDRAZZI,

  • Baixe: <2cb63f5a3cb2891ffea3918328744eaf> (...par Xplode)
  • Ou aqui >>AdwCleaner<<
  • Salve-a na sua Desktop (área de trabalho).
  • Feche todos os programas e navegadores de internet abertos.
  • Usuários do Windows Vista ou Windows 7,clique com o direito do mouse sobre o arquivo AdwCleaner.exe,depois clique em:
    715687bce3607a295707796273fb2e69

    43c99d23e544ec749d16171b30fe4b3c

  • Clique em Examinar, para iniciar o escaneamento!

    c16bf206c6be4697bd007bbcc0ea8fc9
  • Ao término, clique em limpar
  • Copie o log ou clique "Relatório".
  • Poste: >>C:\AdwCleaner\AdwCleaner [S0].txt<<


  • Baixe:<30e722672bdc2a82ab971d6946fd2de0> <(...by Oleg N. Scherbakov)>
  • Salve-o no desktop!
  • Desabilite seu antivírus!
  • Para Windows 7, clique direito em JRT.exe e execute-o como 06b357286306fefd312a9f88ba39d1e6
Imagem
Aguarde a conclusão e poste o relatório. ( JRT.txt )


Um grande abraço. bom_trabalho.gif
PEDRAZZI
PEDRAZZI Novo Membro Registrado
30 Mensagens 0 Curtidas
#7 Por PEDRAZZI
05/02/2015 - 21:31

# AdwCleaner v4.110 - Logfile created 05/02/2015 at 21:22:45
# Updated 05/02/2015 by Xplode
# Database : 2015-02-05.2 [Server]
# Operating system : Windows 8.1 Connected (x64)
# Username : IGOR - IGOR
# Running from : C:\Users\IGOR\Downloads\adwcleaner_4.110.exe
# Option : Cleaning

***** [ Services ] *****

[#] Service Deleted : IHProtect Service

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\XTab

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Google Chrome v40.0.2214.94


-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [10816 bytes] - [27/01/2015 17:53:19]
AdwCleaner[R1].txt - [10877 bytes] - [27/01/2015 18:04:26]
AdwCleaner[R2].txt - [1444 bytes] - [05/02/2015 21:20:34]
AdwCleaner[S0].txt - [9061 bytes] - [27/01/2015 18:09:17]
AdwCleaner[S1].txt - [1494 bytes] - [05/02/2015 21:22:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1553 bytes] ##########
PEDRAZZI
PEDRAZZI Novo Membro Registrado
30 Mensagens 0 Curtidas
#8 Por PEDRAZZI
05/02/2015 - 21:33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 8.1 Connected x64
Ran by IGOR on 05/02/2015 at 21:27:49,55
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05/02/2015 at 21:32:41,31
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
caedurodrigues
caedurodrigu... Tô em todas Registrado
710 Mensagens 257 Curtidas
#9 Por caedurodrigu...
05/02/2015 - 23:37
Boa noite PEDRAZZI,

  • Baixe:<dee34063e0aebc2b75fbd3b18cb7425azoek.exe><(...by Smeenk)>
  • Salve na sua área de trabalho!
  • Execute o arquivo Zoek.exe.
  • Usuários do Windows Vista ou Windows 7 clique com o direito sobre o arquivo Zoek.exe, depois clique em
    06b357286306fefd312a9f88ba39d1e6
  • Selecione as linhas em vermelho, clique com o direito sobre a seleção e escolha a opção copiar!

emptyfolderscheck;delete
ipconfig /flushdns;b
quickscan;
autoclean;
emptyalltemp;


Clique com o direito em qualquer parte branca do Zoek e escolha a opção colar.
Clique Run Script!
Aguarde o scan. Ao final abrirá o bloco de notas com o relatório.
Uma cópia também será salva no seu disco local com o nome zoek-results.txt.
Anexe o zoek-results.txt na sua próxima resposta.

Um grande abraço.
PEDRAZZI
PEDRAZZI Novo Membro Registrado
30 Mensagens 0 Curtidas
#14 Por PEDRAZZI
06/02/2015 - 12:51
~ ZHPCleaner v2015.2.6.52 by Nicolas Coolman (06/02/2015)
~ Run by IGOR (Administrator) (06/02/2015 11:59:05)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\IGOR\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\IGOR\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Windows 81, 64-bit (Build 9600)


---\\ Services (0)
~ No malicious items found.


---\\ Browser internet (1)
REPLACED Chrome URL: "hxxps://www.google.com.br/","hxxp://isearch.omiga-plus.com/?type=hp&ts=1423103134&from=key7&uid=TOS[...]


---\\ Hosts file (0)
~ No malicious items found.


---\\ Scheduled automatic tasks. (0)
~ No malicious items found.


---\\ Explorer ( File, Folder) (2)
MOVED file*: C:\Users\IGOR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_isearch.omiga-plus.com_0.localstorage (Hijacker.OmigaPlus)
MOVED file*: C:\Users\IGOR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_isearch.omiga-plus.com_0.localstorage-journal (Hijacker.OmigaPlus)


---\\ Registry ( Key, Value, Data) (2)
DELETED value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\uTorrent ["C:\Users\IGOR\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED] (Heuristic.KeyRun)
DELETED value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DelayShred ["c:\PROGRA~1\mcafee\mqs\ShrCL.EXE" /P2 /q "C:\Users\IGOR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.omiga-plus.com_0.localstorage-journal" "C:\Users\IGOR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.omiga-plus.com_0.localstorage"] (Hijacker.OmigaPlus)



---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Mozilla Firefox)
~ The system has been restarted.


---\\ Statistics
~ Items scanned : 71040
~ Items found : 0
~ Items repaired : 5


End of clean at 12:09:39
===================
ZHPCleaner-[R]-06022015-12_09_39.txt
ZHPCleaner-[R]-28012015-00_26_49.txt
caedurodrigues
caedurodrigu... Tô em todas Registrado
710 Mensagens 257 Curtidas
#15 Por caedurodrigu...
06/02/2015 - 14:28
Boa tarde PEDRAZZI,

  • Baixe:<1e79137ad22ffc22963ed8e379e7607d> <(...by Farbar)>
  • Ou aqui:<Farbar Recovery Scan Tool 64-bits>
  • Salve-a na Área de trabalho !
  • Execute a ferramenta ! Clique "Yes" >> "Scan".

    edb707f11c612a0ff52862b02fa1aa03
  • Verifique se as caixinhas em "Whitelist" estão assinaladas.
  • Em "Optional Scan",deixe marcada a checkbox "Addition.txt".
  • Será gerado o relatório! (FRST.txt)
  • Ps: Será gerado,também,o relatório "Addition.txt" que estará disponibilizado na 1ª execução da ferramenta.
  • Acesse: <b7cb62cfb007715d3990c0ffc7a9f4ee>
  • Ou acesse:<317c011bca045ff7fc0b26f3766d4d22>
  • Ou anexe-o fórum !
Responder Tópico
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal