Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-08-2015 Ran by Casa (administrator) on CASA-PC (04-05-2016 17:52:48) Running from C:\Users\Casa\Downloads Loaded Profiles: Casa (Available Profiles: Casa & paulo) Platform: Windows 7 Ultimate (X64) Language: Português (Brasil) Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Navigation Co., Ltd.) C:\Users\Casa\AppData\Roaming\ntsvc\ntsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Greenwichers) C:\Program Files\Common Files\Clocker\Clocker.exe () C:\ProgramData\CloudPrinter\CloudPrinter.exe (QNT) C:\Windows\SysWOW64\NetService\netservice.exe () C:\Program Files\PopService\PopService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (iSkySoft) C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Logixoft) C:\ProgramData\rvlkl\rvlkl.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation) HKLM-x32\...\Run: [mbot_br_469] => [X] HKLM-x32\...\Run: [gmsd_br_280] => [X] HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [uTorrent] => C:\Users\Casa\AppData\Roaming\uTorrent\uTorrent.exe [1959424 2016-04-06] (BitTorrent Inc.) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [C] => C:\Windows\system32\GroupPolicy\Machine\Registry.pol [750 2016-02-18] () IFEO\avcenter.exe: [Debugger] nsjw.exe IFEO\avguard.exe: [Debugger] nsjw.exe IFEO\avp.exe: [Debugger] nsjw.exe IFEO\bdagent.exe: [Debugger] nsjw.exe IFEO\ccuac.exe: [Debugger] nsjw.exe IFEO\ComboFix.exe: [Debugger] nsjw.exe IFEO\egui.exe: [Debugger] nsjw.exe IFEO\hijackthis.exe: [Debugger] nsjw.exe IFEO\keyscrambler.exe: [Debugger] nsjw.exe IFEO\mbam.exe: [Debugger] nsjw.exe IFEO\NisSrv.exe: [Debugger] nsjw.exe IFEO\spybotsd.exe: [Debugger] nsjw.exe IFEO\wireshark.exe: [Debugger] nsjw.exe IFEO\zlclient.exe: [Debugger] nsjw.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk [2015-11-17] ShortcutTarget: rvlkl.lnk -> C:\ProgramData\rvlkl\rvlkl.exe (Logixoft) Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-03-02] ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File) InternetURL: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google.com.url -> C:\ProgramData\318983520.exe Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-04-01] ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{9946e5c7-112b-5773-9946-6e5c7112971c}\hqghumeaylnlf.exe (PC Utilities Software Limited) Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de tela e Iniciador do OneNote 2007.lnk [2015-05-12] ShortcutTarget: Recorte de tela e Iniciador do OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => No File ShellIconOverlayIdentifiers: [ExplorerEx] -> {E056AFDD-03E9-4D73-8D33-8FCCBCA73438} => C:\Users\Casa\AppData\Roaming\Macwebtoise\explorerEx64.dll [2015-01-22] () ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] () ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] () ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:65477;https=127.0.0.1:65477; HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID=617911&ResetID=130918373917078690&GUID=68F1EA47-E93E-495D-B174-A3E2733827C8 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKapPZK_Te_JFfpX42ANEwDOSw1XbdrKiKZaTe809gi9uFlS2Oh7xBgLF6Ea9K9ef0oz26JMGtPy_i9B8BFpXEu5PV-KQ, HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.baixaki.com.br/portal/?utm_source=sol&utm_medium=ppi&utm_campaign=portal HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} URLSearchHook: HKLM-x32 - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: [S-1-5-21-3029540503-3706228234-1220206705-1000] ATTENTION ==> Default URLSearchHook is missing SearchScopes: HKLM -> DefaultScope {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> OldSearch URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_bxi01_15_04_ch&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0EyDyCtDyD0ByE0EyDtDyBtN0D0Tzu0StCtCtBtDtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEtCtCzy0AyDtDzytG0E0D0DtCtGzz0CzztCtGzzyD0DyDtGtAzz0A0CtAzy0ByB0E0D0B0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtC0A0A0CtB0F0AtGtA0Ezy0CtGyE0AtA0AtGzyzy0C0AtG0AyDtByCtDtB0CyDyD0FyDyC2Q&cr=452709962&ir= SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=320&itype=a&ver=15005&tm=603&src=ds&p={searchTerms} SearchScopes: HKLM -> {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=320&itype=a&ver=15005&tm=603&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.thesearchpage.info/?l=1&q={searchTerms}&pid=2457&r=2015/01/15&hid=10016137845286072043&lg=EN&cc=BR&unqvl=74 SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> DefaultScope {ielnksrch} URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> OldSearch URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q= SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {B9A0191A-DF8A-47B4-B8F6-9937EF2702DE} URL = http://br.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_15¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDzzyCtDyC0EyDyCtDyD0ByE0EyDtDyBtN0D0Tzu0StCtCzzyEtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyE0F0BtDtAyE0DtG0F0AtD0DtG0CzytA0DtGyCzyzyzztGyD0B0B0D0ByEzztB0ByB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtC0A0A0CtB0F0AtGtA0Ezy0CtGyE0AtA0AtGzyzy0C0AtG0AyDtByCtDtB0CyDyD0FyDyC2QtN0A0LzutB%26cr%3D1734649387%26a%3Dwny_ir_15_15%26os%3DWindows 7 Ultimate&p={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {BE8EBFCD-B0E2-415E-AB48-B6F5EFE6494B} URL = http://www.search.ask.com/web?tpid=ATU4SP-MED&o=APN11391&pf=V7&p2=^BAY^YYYYYY^YY^BR&gct=sb&itbv=12.28.1.1226&apn_uid=D646F06B-8F0F-409F-A544-A26A5033C0C9&apn_ptnrs=^BAY&apn_dtid=^YYYYYY^YY^BR&apn_dbr=cr_42.0.2311.152&doi=2015-05-17&trgb=CR&q={searchTerms}&psv=&pt=tb SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {E4E012DC-1925-48E9-8010-2D195574642A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {ielnksrch} URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) Toolbar: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> No Name - {41545534-2D53-5000-76A7-7A786E7484D7} - No File Toolbar: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> No Name - {41545534-5350-2D4D-4544-7A786E7484D7} - No File Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) Handler: WSISVCUchrome - No CLSID Value Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-12-21] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-12-21] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-12-21] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-12-21] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{51902F85-692E-4225-B885-C62B9E8245F4}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{51902F85-692E-4225-B885-C62B9E8245F4}: [DhcpNameServer] 192.168.1.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default FF NewTab: C:\\ProgramData\\Sailitys\\ff.NT FF DefaultSearchEngine: findit FF DefaultSearchEngine,S: WebSearch FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?pid=23765&r=2015/07/02&hid=10016137845286072043&lg=EN&cc=BR&unqvl=90&l=1&q= FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.1,S: WebSearch FF SelectedSearchEngine: Default FF SelectedSearchEngine,S: WebSearch FF Homepage: C:\\ProgramData\\Sailitys\\ff.HP FF Keyword.URL: hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgPUQgVFwZCbQELUQ5cFQdCdxRaWFoSDFcXI1tcVloSQAYWeB9aFQQTR0cFME0FB18EURNNfWpdBGsUUkBPNEpwFFs=&q={searchTerms} FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-12-17] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-12-17] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-11-18] (Adobe Systems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Casa\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall) FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Casa\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File] FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-19] (Google Inc.) FF Plugin HKU\S-1-5-21-3029540503-3706228234-1220206705-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Casa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-10] (Unity Technologies ApS) FF user.js: detected! => C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\user.js [2015-10-29] FF SearchPlugin: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\searchplugins\findit.xml [2016-02-18] FF SearchPlugin: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\searchplugins\WebSearch.xml [2015-07-07] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\findit.xml [2016-02-18] FF Extension: Yellow AdBlocker - C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\Extensions\gdodupagpoubevx@_iuymmxdcefubaho.net [2015-08-21] FF Extension: GreatSAvve4U - C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\Extensions\NJCJol@vakvs.edu [2015-08-21] FF HKLM\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox FF HKLM-x32\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found] Chrome: ======= CHR Profile: C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-08] CHR Extension: (YouTube) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-08] CHR Extension: (Google Search) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-08] CHR Extension: (Gmail) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-08] CHR Profile: C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Drive) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-12] CHR Extension: (Video Game Truck Advertising) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\befkjchdmahejikgbnefikmbeahhippp [2016-05-04] CHR Extension: (YouTube) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-19] CHR Extension: (Google Search) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-12] CHR Extension: (Chrome Web Store Payments) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-19] CHR Extension: (Gmail) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-19] CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fgbcffenncokfocljomejddmgcpppjom] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 ClockerService; C:\Program Files\Common Files\Clocker\Clocker.exe [77824 2015-01-28] (Greenwichers) [File not signed] R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [667136 2016-02-18] () [File not signed] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R2 MyLocalService; C:\Windows\SysWOW64\NetService\netservice.exe [226888 2015-01-20] (QNT) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [275752 2008-01-22] (Nero AG) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1286896 2016-04-05] (Overwolf LTD) R2 PopService; C:\Program Files\PopService\PopService.exe [38464 2015-05-22] () R2 Sed; C:\Users\Casa\AppData\Roaming\ntsvc\ntsvc.exe [388072 2015-05-21] (Navigation Co., Ltd.) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 crfilterdrv; C:\Windows\System32\drivers\crfilterdrv.sys [51528 2015-02-25] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-28] (Disc Soft Ltd) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) R1 pofilterdrv; C:\Windows\System32\drivers\pofilterdrv.sys [60736 2015-01-19] (NetFilterSDK.com) S1 bmekvmlw; \??\C:\Windows\system32\drivers\bmekvmlw.sys [X] S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X] S1 ccnfd_1_10_0_5; system32\drivers\ccnfd_1_10_0_5.sys [X] S1 cherimoya; system32\drivers\cherimoya.sys [X] S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\5.0.0.0\PCFApiUtil64.sys [X] S1 wsfd_1_10_0_17; system32\drivers\wsfd_1_10_0_17.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-05-04 17:52 - 2016-05-04 17:53 - 00028869 _____ C:\Users\Casa\Downloads\FRST.txt 2016-05-04 17:52 - 2016-05-04 17:53 - 00000000 ____D C:\FRST 2016-05-04 17:51 - 2016-05-04 17:51 - 02170368 _____ (Farbar) C:\Users\Casa\Downloads\frst64.exe 2016-05-04 17:50 - 2016-05-04 17:50 - 01728000 _____ (Farbar) C:\Users\Casa\Downloads\FRST.exe 2016-05-04 17:26 - 2016-05-04 17:43 - 00000000 ___RD C:\Users\Casa\Desktop\Cemu 1.4.2b Fixed 2016-05-04 17:25 - 2016-05-04 17:25 - 15870928 _____ C:\Users\Casa\Downloads\Cemu 1.4.2b Fixed.rar 2016-05-04 17:20 - 2016-05-04 17:20 - 00001052 _____ C:\Users\Casa\Desktop\MEGAsync.lnk 2016-05-04 17:20 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync 2016-05-04 17:20 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Local\Mega Limited 2016-05-04 17:19 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Local\MEGAsync 2016-05-04 17:18 - 2016-05-04 17:19 - 11944801 _____ C:\Users\Casa\Downloads\citra-latest-windows-amd64.7z 2016-05-04 17:14 - 2016-05-04 17:16 - 10629936 _____ (MEGA Limited) C:\Users\Casa\Downloads\MEGAsyncSetup.exe 2016-05-04 17:13 - 2016-05-04 17:15 - 14572000 _____ (Microsoft Corporation) C:\Users\Casa\Downloads\vc_redist.x64.exe 2016-05-03 19:39 - 2016-05-03 19:39 - 03750018 _____ C:\Users\Casa\Downloads\content.rar 2016-05-03 19:18 - 2016-05-03 19:18 - 01735558 _____ C:\Users\Casa\Downloads\cemu_1.4.0 (2).zip 2016-05-03 18:44 - 2016-05-03 18:44 - 00000000 ____D C:\Users\Casa\Desktop\Emulador de Controle Tomb Raider - x360ce - Cópia 2016-05-03 18:04 - 2016-05-03 18:04 - 00000000 ____D C:\Users\Casa\Desktop\CemuMod Fusion Ver 1.0 2016-05-03 18:03 - 2016-05-03 18:03 - 00001015 _____ C:\Users\Casa\Downloads\Cemu 1.4.0 Fix Version 1.0 Luigui U por Inmortalgames (1).txt 2016-05-03 18:03 - 2016-04-30 20:11 - 00000028 _____ C:\Users\Casa\Desktop\serial.bin 2016-05-03 18:02 - 2016-05-03 18:03 - 10414123 _____ C:\Users\Casa\Downloads\CemuMod Fusion Ver 1.0.rar 2016-05-03 06:32 - 2016-05-03 06:32 - 00083796 _____ C:\Users\Casa\Downloads\Super.Mario.3D.World.USA.WiiU-PoWeRUp-7z.torrent 2016-05-02 17:04 - 2016-05-04 17:43 - 00002060 _____ C:\Users\Casa\Desktop\Google Chrome.lnk 2016-05-02 16:32 - 2016-05-02 16:32 - 01735558 _____ C:\Users\Casa\Downloads\cemu_1.4.0.zip 2016-05-02 16:22 - 2016-05-02 16:21 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2016-05-01 17:52 - 2016-05-01 17:52 - 07496523 _____ C:\Users\Casa\Downloads\58759762316322 (1).rar 2016-05-01 17:51 - 2016-05-01 18:15 - 00000000 ____D C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY 2016-05-01 17:51 - 2016-05-01 17:51 - 00024461 _____ C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY.torrent 2016-05-01 17:30 - 2016-05-01 17:30 - 00001015 _____ C:\Users\Casa\Downloads\Cemu 1.4.0 Fix Version 1.0 Luigui U por Inmortalgames.txt 2016-05-01 17:30 - 2016-05-01 17:30 - 00001008 _____ C:\Users\Casa\Downloads\Cemu 1.4.2 Version Oficial por Inmortalgames.txt 2016-04-30 17:31 - 2016-05-03 06:44 - 00000000 ____D C:\Users\Casa\Downloads\Shadow_Warrior-FLT 2016-04-30 17:19 - 2016-04-30 17:19 - 00023086 _____ C:\Users\Casa\Downloads\shadow-warrior-special-edition-multi11pcdvdprophet.torrent 2016-04-29 18:02 - 2016-04-29 18:35 - 00000000 ____D C:\Users\Casa\Downloads\Costume.Quest.v1.0.11.MacOSX.READNFO-EZGAME.www.GamesTorrents.com 2016-04-29 18:01 - 2016-04-29 18:01 - 00012048 _____ C:\Users\Casa\Downloads\costumequestv1011macosxreadnfo-ezgame[www.gamestorrent.biz] (1).torrent 2016-04-28 19:27 - 2016-04-28 19:27 - 00072851 _____ C:\Users\Casa\Downloads\COSTUME.QUEST.2.V1.0.ALL.RITUEL.NODVD.ZIP 2016-04-28 19:25 - 2016-04-28 19:26 - 00918688 _____ C:\Users\Casa\Downloads\d3dx9.zip 2016-04-28 18:15 - 2016-04-28 18:15 - 00012048 _____ C:\Users\Casa\Downloads\costumequestv1011macosxreadnfo-ezgame[www.gamestorrent.biz].torrent 2016-04-28 06:55 - 2016-04-28 06:55 - 00000000 ____D C:\Users\Casa\Downloads\Alan.Wake-SKIDROW 2016-04-27 19:14 - 2016-04-27 19:14 - 00000000 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (5).txt 2016-04-27 18:58 - 2016-04-27 18:58 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Doublefine 2016-04-27 17:46 - 2016-04-27 17:46 - 00000593 _____ C:\Users\Casa\Desktop\Cemu - Atalho.lnk 2016-04-27 17:40 - 2016-04-27 17:40 - 07496523 _____ C:\Users\Casa\Downloads\new super mario bros u fix.rar 2016-04-27 10:53 - 2016-04-27 10:53 - 00001724 _____ C:\Users\Casa\Downloads\Castlevania Lords Of Shadow 2 [MULTI6][PCDVD][Repack BlackBox][WwW.GamesTorrents.CoM] - Atalho.lnk 2016-04-27 10:53 - 2016-04-27 10:53 - 00001409 _____ C:\Users\Casa\Downloads\New Super Luigi U [EUR] MULTi8 Loadiine READY2PLAY - Atalho.lnk 2016-04-27 10:53 - 2016-04-27 10:53 - 00001391 _____ C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY - Atalho.lnk 2016-04-26 19:14 - 2016-04-27 18:51 - 980795931 ____R (Игры на Cat-A-Cat.NET ) C:\Users\Casa\Downloads\Costume Quest 2.exe 2016-04-26 16:39 - 2016-04-26 17:49 - 00000000 ____D C:\Users\Casa\Downloads\State.of.Decay-WaLMaRT 2016-04-26 06:45 - 2016-04-26 07:12 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 3 Temporada - The Pirate Filmes 2016-04-26 06:45 - 2016-04-26 07:03 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 2 Temporada - The Pirate Filmes 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Todos os Usuários\.mono 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Casa\AppData\Roaming\.mono 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\ProgramData\.mono 2016-04-25 19:16 - 2016-04-25 19:16 - 00017483 _____ C:\Windows\DirectX.log 2016-04-25 18:37 - 2016-05-02 00:50 - 00000910 _____ C:\Users\Casa\Desktop\Novo Documento de Texto.txt 2016-04-25 05:34 - 2016-04-25 05:34 - 00039324 _____ C:\Users\Casa\Desktop\doença.htm 2016-04-24 18:40 - 2016-04-25 18:42 - 00000000 ____D C:\Program Files (x86)\Remedy Entertainment 2016-04-24 17:32 - 2016-04-24 17:33 - 00000000 ____D C:\Users\Casa\Desktop\Uma familia da pesada 2016-04-23 11:27 - 2016-04-23 11:27 - 00000000 ____D C:\Users\Casa\Documents\League of Legends 2016-04-23 08:38 - 2016-04-23 08:38 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-04-23 08:38 - 2016-04-23 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewFeature1 2016-04-23 08:37 - 2016-04-23 08:37 - 00000000 ____D C:\Users\Casa\Desktop\League of Legends 2016-04-22 19:45 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2016-04-22 19:45 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2016-04-22 19:45 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2016-04-22 19:44 - 2016-04-22 19:44 - 00000000 ____D C:\Riot Games 2016-04-22 16:18 - 2016-04-22 16:18 - 00000000 ____D C:\Users\Casa\Downloads\The.Walking.Dead.S06E01.PROPER.720p.HDTV.x264-KILLERS[rarbg] 2016-04-20 01:54 - 2016-04-20 02:10 - 00000000 ____D C:\Users\Casa\Downloads\Inatividade Paranormal (www.thePirateFilmes.com) 2016-04-19 06:54 - 2016-04-21 19:23 - 00000000 ____D C:\Users\Casa\Desktop\beelzebub 2016-04-19 06:43 - 2016-04-19 06:46 - 00000000 ____D C:\Users\Casa\Downloads\Inatividade Paranormal 2.(2014).Dublado.1080p.By.Luan.Harper 2016-04-16 18:29 - 2016-04-21 23:08 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 1 Temporada - The Pirate Filmes 2016-04-16 13:39 - 2016-04-16 13:39 - 00000408 _____ C:\Windows\Tasks\Overwolf Updater Task.job 2016-04-16 13:39 - 2016-04-16 13:39 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2016-04-16 13:39 - 2016-04-16 13:39 - 00000000 ____D C:\Program Files (x86)\Overwolf 2016-04-16 13:38 - 2016-04-16 13:39 - 00000000 ____D C:\Users\Todos os Usuários\Overwolf 2016-04-16 13:38 - 2016-04-16 13:39 - 00000000 ____D C:\ProgramData\Overwolf 2016-04-16 13:37 - 2016-04-30 09:13 - 00000000 ____D C:\Users\Casa\AppData\Roaming\TS3Client 2016-04-16 13:37 - 2016-04-16 13:44 - 00000000 ____D C:\Users\Casa\AppData\Local\Overwolf 2016-04-16 13:37 - 2016-04-16 13:37 - 00000967 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2016-04-16 13:37 - 2016-04-16 13:37 - 00000929 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk 2016-04-16 13:37 - 2016-04-16 13:37 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2016-04-15 09:59 - 2016-04-16 13:27 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client 2016-04-14 19:29 - 2016-04-22 16:22 - 00000000 ____D C:\Users\Casa\Downloads\Uma.Aventura.Animal.na.Terra.do.Vento.2015.HDRip.XviD.Dublado-OSR 2016-04-14 12:10 - 2016-05-01 18:07 - 00000000 ____D C:\Users\Casa\Desktop\cemu_1.4.1 2016-04-14 12:10 - 2016-04-14 12:10 - 01742620 _____ C:\Users\Casa\Downloads\cemu_1.4.1.zip 2016-04-09 02:14 - 2016-04-09 02:37 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural - 10ª Temporada (2015) BluRay BDrip 720p Dual Áudio - HipnosTPF 2016-04-06 20:01 - 2016-04-24 19:18 - 00000000 ____D C:\Program Files (x86)\Dishonored ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-05-04 17:52 - 2015-03-03 10:40 - 01371832 _____ C:\Windows\WindowsUpdate.log 2016-05-04 17:17 - 2016-01-29 05:21 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2016-05-04 17:17 - 2016-01-29 05:21 - 00000000 ____D C:\ProgramData\Package Cache 2016-05-04 17:17 - 2014-12-28 11:12 - 00000000 ____D C:\Users\Casa\AppData\Roaming\uTorrent 2016-05-04 07:21 - 2015-01-28 09:28 - 00000000 ____D C:\Users\Todos os Usuários\rvlkl 2016-05-04 07:21 - 2015-01-28 09:28 - 00000000 ____D C:\ProgramData\rvlkl 2016-05-04 06:45 - 2015-11-12 05:33 - 00000000 ____D C:\Program Files (x86)\Steam 2016-05-04 05:07 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-05-04 05:07 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-05-04 05:02 - 2015-03-22 16:22 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Skype 2016-05-04 04:59 - 2016-03-29 05:04 - 00012798 _____ C:\Windows\setupact.log 2016-05-03 18:15 - 2016-03-13 17:49 - 00000000 ____D C:\Users\Casa\Downloads\Super.Mario.3D.World.USA.WiiU-PoWeRUp-7z 2016-05-02 22:43 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\system32\NDF 2016-05-02 16:21 - 2016-02-19 18:24 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-05-01 22:35 - 2015-07-04 10:42 - 00000684 _____ C:\Users\Casa\Desktop\997027960.txt 2016-04-30 19:12 - 2015-11-25 03:22 - 00000000 ____D C:\Games 2016-04-30 18:51 - 2009-07-14 14:55 - 00709738 _____ C:\Windows\system32\prfh0416.dat 2016-04-30 18:51 - 2009-07-14 14:55 - 00149354 _____ C:\Windows\system32\prfc0416.dat 2016-04-30 18:51 - 2009-07-14 02:13 - 01647490 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-28 14:41 - 2014-12-27 17:11 - 00000000 ____D C:\Users\Casa 2016-04-28 14:39 - 2016-03-07 17:21 - 00000000 ____D C:\Users\paulo.Casa-PC 2016-04-28 14:39 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\registration 2016-04-27 17:41 - 2016-03-29 20:06 - 00000000 ____D C:\Users\Casa\Desktop\fairy tail 2016-04-25 19:43 - 2015-01-13 16:43 - 00000000 ____D C:\Users\Casa\Desktop\anderson freire 2016-04-25 19:31 - 2015-07-30 00:54 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-04-24 19:17 - 2016-02-23 18:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2016-04-24 19:17 - 2016-02-23 18:26 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics 2016-04-24 19:17 - 2015-09-30 18:02 - 00000000 ____D C:\Users\Casa\Documents\My Games 2016-04-24 19:17 - 2015-01-19 10:53 - 00000000 ____D C:\Users\Casa\AppData\Local\SKIDROW 2016-04-23 11:07 - 2015-07-31 14:07 - 00000000 ____D C:\Users\Casa\AppData\Roaming\LolClient 2016-04-22 19:46 - 2015-07-31 02:26 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Riot Games 2016-04-22 04:57 - 2014-12-28 10:24 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-04-15 14:29 - 2016-03-23 19:00 - 00000310 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (4).txt 2016-04-11 21:42 - 2015-09-22 19:25 - 00001954 _____ C:\Users\Casa\Desktop\RCGamebox.lnk 2016-04-05 19:09 - 2014-12-28 18:16 - 00000000 ____D C:\Users\Casa\AppData\Roaming\DAEMON Tools Lite ==================== Files in the root of some directories ======= 2015-06-06 09:47 - 2015-06-06 09:53 - 0000183 _____ () C:\Program Files\Common Files\Novo Documento de Texto.txt 2015-05-18 16:32 - 2015-05-21 23:09 - 0000109 _____ () C:\Program Files (x86)\Common Files\Novo Documento de Texto.txt 2016-02-18 18:52 - 2016-02-18 18:52 - 7951360 _____ () C:\Users\Casa\AppData\Roaming\agent.dat 2015-06-16 01:16 - 2015-08-21 12:56 - 0000024 _____ () C:\Users\Casa\AppData\Roaming\appdataFr25.bin 2015-02-26 18:16 - 2015-05-14 23:36 - 0000020 _____ () C:\Users\Casa\AppData\Roaming\appdataFr3.bin 2016-02-18 18:52 - 2016-02-18 18:52 - 0054272 _____ () C:\Users\Casa\AppData\Roaming\ApplicationHosting.dat 2016-02-18 18:48 - 2016-02-18 18:49 - 0001344 _____ () C:\Users\Casa\AppData\Roaming\Bubble Dock.boostrap.log 2016-02-18 18:48 - 2016-02-18 18:48 - 0005707 _____ () C:\Users\Casa\AppData\Roaming\Bubble Dock.installation.log 2015-05-10 09:00 - 2015-05-10 09:00 - 0154283 ____H () C:\Users\Casa\AppData\Roaming\Casa-wchelper.dll 2016-02-18 18:52 - 2016-02-18 18:52 - 0063696 _____ () C:\Users\Casa\AppData\Roaming\Config.xml 2015-07-11 08:20 - 2016-02-24 12:38 - 0002725 _____ () C:\Users\Casa\AppData\Roaming\droid4xinstaller.log 2015-06-14 17:29 - 2015-06-14 17:29 - 1322672 _____ () C:\Users\Casa\AppData\Roaming\GameHouse-Installer_am-cuttherope_gamehouse_.exe 2016-02-18 18:49 - 2016-02-18 18:50 - 0016992 _____ () C:\Users\Casa\AppData\Roaming\InstallationConfiguration.xml 2016-02-18 18:49 - 2016-02-18 18:49 - 0126976 _____ () C:\Users\Casa\AppData\Roaming\Installer.dat 2015-04-14 13:28 - 2015-04-14 13:28 - 0001171 _____ () C:\Users\Casa\AppData\Roaming\Kx7lf0Ji0oXH 2015-04-20 11:05 - 2015-04-20 11:05 - 1246720 _____ () C:\Users\Casa\AppData\Roaming\Kx7lf0Ji0oXH.exe 2016-02-18 18:52 - 2016-02-18 18:52 - 0126464 _____ () C:\Users\Casa\AppData\Roaming\lobby.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 0018432 _____ () C:\Users\Casa\AppData\Roaming\Main.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 0005568 _____ () C:\Users\Casa\AppData\Roaming\md.xml 2015-06-14 17:30 - 2015-10-26 05:53 - 0400728 _____ () C:\Users\Casa\AppData\Roaming\msconfig.ini 2016-02-18 18:52 - 2016-02-18 18:52 - 0126464 _____ () C:\Users\Casa\AppData\Roaming\noah.dat 2016-02-18 18:52 - 2016-02-18 18:49 - 0667136 _____ () C:\Users\Casa\AppData\Roaming\Over-La.exe 2016-02-18 18:52 - 2016-02-18 18:52 - 1882213 _____ () C:\Users\Casa\AppData\Roaming\Over-La.tst 2016-02-18 18:49 - 2016-02-18 18:49 - 0000078 _____ () C:\Users\Casa\AppData\Roaming\Selection Tools.installation.log 2016-01-08 08:10 - 2016-01-08 08:10 - 0000001 _____ () C:\Users\Casa\AppData\Roaming\smw_inst 2016-02-18 18:52 - 2016-02-18 18:49 - 0667136 _____ () C:\Users\Casa\AppData\Roaming\TranKeylax.exe 2016-02-18 18:52 - 2016-02-18 18:52 - 0072777 _____ () C:\Users\Casa\AppData\Roaming\TranKeylax.tst 2016-02-18 18:51 - 2016-02-18 18:51 - 0848437 _____ () C:\Users\Casa\AppData\Roaming\Trustron.bin 2016-02-18 18:52 - 2016-02-18 18:52 - 0188584 _____ () C:\Users\Casa\AppData\Roaming\U-lux.bin 2016-02-18 18:53 - 2016-02-18 18:53 - 0032038 _____ () C:\Users\Casa\AppData\Roaming\uninstall_temp.ico 2015-03-30 10:25 - 2015-03-31 00:25 - 0000069 _____ () C:\Users\Casa\AppData\Roaming\WB.CFG 2016-02-18 18:48 - 2016-02-18 18:48 - 0000097 _____ () C:\Users\Casa\AppData\Roaming\WindApp.boostrap.log 2016-02-18 18:48 - 2016-02-18 18:49 - 0000078 _____ () C:\Users\Casa\AppData\Roaming\WindApp.installation.log 2015-01-18 09:07 - 2015-01-18 09:07 - 0000000 ___SH () C:\Users\Casa\AppData\Local\LumaEmu 2015-12-24 18:38 - 2015-12-24 18:38 - 0000017 _____ () C:\Users\Casa\AppData\Local\resmon.resmoncfg 2015-03-19 16:07 - 2015-04-22 08:17 - 0011662 _____ () C:\Users\Casa\AppData\Local\Temp-log.txt 2015-02-19 20:59 - 2015-02-19 20:59 - 0000227 _____ () C:\ProgramData\bc.ini Files to move or delete: ==================== C:\Users\Casa\AppData\Roaming\msconfig.ini C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job C:\Windows\Tasks\{38AE8803-5DFC-46DC-B239-E31F33E05F68}.job C:\Windows\Tasks\{DE2ABF7F-8BAB-4F89-BF73-1F181918DB64}.job Some files in TEMP: ==================== C:\Users\Casa\AppData\Local\Temp\ICReinstall_American_McGee_s_Grimm_GOG_PC_FullDownGames.exe C:\Users\Casa\AppData\Local\Temp\utils.dll C:\Users\Casa\AppData\Local\Temp\ytd_sysmenu_setup.exe Some zero byte size files/folders: ========================== C:\Windows\SysWOW64\ahstock2a.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-13 03:20 ==================== End of log ============================