cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-08-2015
Ran by Casa (administrator) on CASA-PC (04-05-2016 17:52:48)
Running from C:\Users\Casa\Downloads
Loaded Profiles: Casa (Available Profiles: Casa & paulo)
Platform: Windows 7 Ultimate (X64) Language: Português (Brasil)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Navigation Co., Ltd.) C:\Users\Casa\AppData\Roaming\ntsvc\ntsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Greenwichers) C:\Program Files\Common Files\Clocker\Clocker.exe
() C:\ProgramData\CloudPrinter\CloudPrinter.exe
(QNT) C:\Windows\SysWOW64\NetService\netservice.exe
() C:\Program Files\PopService\PopService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(iSkySoft) C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Logixoft) C:\ProgramData\rvlkl\rvlkl.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation)
HKLM-x32\...\Run: [mbot_br_469] => [X]
HKLM-x32\...\Run: [gmsd_br_280] => [X]
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [uTorrent] => C:\Users\Casa\AppData\Roaming\uTorrent\uTorrent.exe [1959424 2016-04-06] (BitTorrent Inc.)
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [C] => C:\Windows\system32\GroupPolicy\Machine\Registry.pol [750 2016-02-18] ()
IFEO\avcenter.exe: [Debugger] nsjw.exe
IFEO\avguard.exe: [Debugger] nsjw.exe
IFEO\avp.exe: [Debugger] nsjw.exe
IFEO\bdagent.exe: [Debugger] nsjw.exe
IFEO\ccuac.exe: [Debugger] nsjw.exe
IFEO\ComboFix.exe: [Debugger] nsjw.exe
IFEO\egui.exe: [Debugger] nsjw.exe
IFEO\hijackthis.exe: [Debugger] nsjw.exe
IFEO\keyscrambler.exe: [Debugger] nsjw.exe
IFEO\mbam.exe: [Debugger] nsjw.exe
IFEO\NisSrv.exe: [Debugger] nsjw.exe
IFEO\spybotsd.exe: [Debugger] nsjw.exe
IFEO\wireshark.exe: [Debugger] nsjw.exe
IFEO\zlclient.exe: [Debugger] nsjw.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk [2015-11-17]
ShortcutTarget: rvlkl.lnk -> C:\ProgramData\rvlkl\rvlkl.exe (Logixoft)
Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-03-02]
ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File)
InternetURL: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google.com.url -> C:\ProgramData\318983520.exe
Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-04-01]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{9946e5c7-112b-5773-9946-6e5c7112971c}\hqghumeaylnlf.exe (PC Utilities Software Limited)
Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de tela e Iniciador do OneNote 2007.lnk [2015-05-12]
ShortcutTarget: Recorte de tela e Iniciador do OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => No File
ShellIconOverlayIdentifiers: [ExplorerEx] -> {E056AFDD-03E9-4D73-8D33-8FCCBCA73438} => C:\Users\Casa\AppData\Roaming\Macwebtoise\explorerEx64.dll [2015-01-22] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:65477;https=127.0.0.1:65477;
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID=617911&ResetID=130918373917078690&GUID=68F1EA47-E93E-495D-B174-A3E2733827C8
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms}
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms}
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKapPZK_Te_JFfpX42ANEwDOSw1XbdrKiKZaTe809gi9uFlS2Oh7xBgLF6Ea9K9ef0oz26JMGtPy_i9B8BFpXEu5PV-KQ,
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.baixaki.com.br/portal/?utm_source=sol&utm_medium=ppi&utm_campaign=portal
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms}
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q={searchTerms}
HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms}
URLSearchHook: HKLM-x32 - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
URLSearchHook: [S-1-5-21-3029540503-3706228234-1220206705-1000] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> OldSearch URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_bxi01_15_04_ch&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0EyDyCtDyD0ByE0EyDtDyBtN0D0Tzu0StCtCtBtDtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEtCtCzy0AyDtDzytG0E0D0DtCtGzz0CzztCtGzzyD0DyDtGtAzz0A0CtAzy0ByB0E0D0B0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtC0A0A0CtB0F0AtGtA0Ezy0CtGyE0AtA0AtGzyzy0C0AtG0AyDtByCtDtB0CyDyD0FyDyC2Q&cr=452709962&ir=
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL =
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=320&itype=a&ver=15005&tm=603&src=ds&p={searchTerms}
SearchScopes: HKLM -> {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=320&itype=a&ver=15005&tm=603&src=ds&p={searchTerms}
SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.thesearchpage.info/?l=1&q={searchTerms}&pid=2457&r=2015/01/15&hid=10016137845286072043&lg=EN&cc=BR&unqvl=74
SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> DefaultScope {ielnksrch} URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> OldSearch URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q=
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {B9A0191A-DF8A-47B4-B8F6-9937EF2702DE} URL = http://br.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_15¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDzzyCtDyC0EyDyCtDyD0ByE0EyDtDyBtN0D0Tzu0StCtCzzyEtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyE0F0BtDtAyE0DtG0F0AtD0DtG0CzytA0DtGyCzyzyzztGyD0B0B0D0ByEzztB0ByB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtC0A0A0CtB0F0AtGtA0Ezy0CtGyE0AtA0AtGzyzy0C0AtG0AyDtByCtDtB0CyDyD0FyDyC2QtN0A0LzutB%26cr%3D1734649387%26a%3Dwny_ir_15_15%26os%3DWindows 7 Ultimate&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {BE8EBFCD-B0E2-415E-AB48-B6F5EFE6494B} URL = http://www.search.ask.com/web?tpid=ATU4SP-MED&o=APN11391&pf=V7&p2=^BAY^YYYYYY^YY^BR&gct=sb&itbv=12.28.1.1226&apn_uid=D646F06B-8F0F-409F-A544-A26A5033C0C9&apn_ptnrs=^BAY&apn_dtid=^YYYYYY^YY^BR&apn_dbr=cr_42.0.2311.152&doi=2015-05-17&trgb=CR&q={searchTerms}&psv=&pt=tb
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {E4E012DC-1925-48E9-8010-2D195574642A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {ielnksrch} URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms}
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> No Name - {41545534-2D53-5000-76A7-7A786E7484D7} - No File
Toolbar: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> No Name - {41545534-5350-2D4D-4544-7A786E7484D7} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Handler: WSISVCUchrome - No CLSID Value
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-12-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-12-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-12-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-12-21] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{51902F85-692E-4225-B885-C62B9E8245F4}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{51902F85-692E-4225-B885-C62B9E8245F4}: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default
FF NewTab: C:\\ProgramData\\Sailitys\\ff.NT
FF DefaultSearchEngine: findit
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?pid=23765&r=2015/07/02&hid=10016137845286072043&lg=EN&cc=BR&unqvl=90&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: Default
FF SelectedSearchEngine,S: WebSearch
FF Homepage: C:\\ProgramData\\Sailitys\\ff.HP
FF Keyword.URL: hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgPUQgVFwZCbQELUQ5cFQdCdxRaWFoSDFcXI1tcVloSQAYWeB9aFQQTR0cFME0FB18EURNNfWpdBGsUUkBPNEpwFFs=&q={searchTerms}
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-12-17] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-12-17] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-11-18] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Casa\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Casa\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-3029540503-3706228234-1220206705-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Casa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-10] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\user.js [2015-10-29]
FF SearchPlugin: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\searchplugins\findit.xml [2016-02-18]
FF SearchPlugin: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\searchplugins\WebSearch.xml [2015-07-07]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\findit.xml [2016-02-18]
FF Extension: Yellow AdBlocker - C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\Extensions\gdodupagpoubevx@_iuymmxdcefubaho.net [2015-08-21]
FF Extension: GreatSAvve4U - C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\Extensions\NJCJol@vakvs.edu [2015-08-21]
FF HKLM\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]

Chrome:
=======
CHR Profile: C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-08]
CHR Extension: (YouTube) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-08]
CHR Extension: (Google Search) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-08]
CHR Extension: (Gmail) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-08]
CHR Profile: C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-12]
CHR Extension: (Video Game Truck Advertising) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\befkjchdmahejikgbnefikmbeahhippp [2016-05-04]
CHR Extension: (YouTube) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-19]
CHR Extension: (Google Search) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-19]
CHR Extension: (Gmail) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-19]
CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fgbcffenncokfocljomejddmgcpppjom] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 ClockerService; C:\Program Files\Common Files\Clocker\Clocker.exe [77824 2015-01-28] (Greenwichers) [File not signed]
R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [667136 2016-02-18] () [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R2 MyLocalService; C:\Windows\SysWOW64\NetService\netservice.exe [226888 2015-01-20] (QNT)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [275752 2008-01-22] (Nero AG)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1286896 2016-04-05] (Overwolf LTD)
R2 PopService; C:\Program Files\PopService\PopService.exe [38464 2015-05-22] ()
R2 Sed; C:\Users\Casa\AppData\Roaming\ntsvc\ntsvc.exe [388072 2015-05-21] (Navigation Co., Ltd.)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 crfilterdrv; C:\Windows\System32\drivers\crfilterdrv.sys [51528 2015-02-25] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-28] (Disc Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R1 pofilterdrv; C:\Windows\System32\drivers\pofilterdrv.sys [60736 2015-01-19] (NetFilterSDK.com)
S1 bmekvmlw; \??\C:\Windows\system32\drivers\bmekvmlw.sys [X]
S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
S1 ccnfd_1_10_0_5; system32\drivers\ccnfd_1_10_0_5.sys [X]
S1 cherimoya; system32\drivers\cherimoya.sys [X]
S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\5.0.0.0\PCFApiUtil64.sys [X]
S1 wsfd_1_10_0_17; system32\drivers\wsfd_1_10_0_17.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-04 17:52 - 2016-05-04 17:53 - 00028869 _____ C:\Users\Casa\Downloads\FRST.txt
2016-05-04 17:52 - 2016-05-04 17:53 - 00000000 ____D C:\FRST
2016-05-04 17:51 - 2016-05-04 17:51 - 02170368 _____ (Farbar) C:\Users\Casa\Downloads\frst64.exe
2016-05-04 17:50 - 2016-05-04 17:50 - 01728000 _____ (Farbar) C:\Users\Casa\Downloads\FRST.exe
2016-05-04 17:26 - 2016-05-04 17:43 - 00000000 ___RD C:\Users\Casa\Desktop\Cemu 1.4.2b Fixed
2016-05-04 17:25 - 2016-05-04 17:25 - 15870928 _____ C:\Users\Casa\Downloads\Cemu 1.4.2b Fixed.rar
2016-05-04 17:20 - 2016-05-04 17:20 - 00001052 _____ C:\Users\Casa\Desktop\MEGAsync.lnk
2016-05-04 17:20 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
2016-05-04 17:20 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Local\Mega Limited
2016-05-04 17:19 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Local\MEGAsync
2016-05-04 17:18 - 2016-05-04 17:19 - 11944801 _____ C:\Users\Casa\Downloads\citra-latest-windows-amd64.7z
2016-05-04 17:14 - 2016-05-04 17:16 - 10629936 _____ (MEGA Limited) C:\Users\Casa\Downloads\MEGAsyncSetup.exe
2016-05-04 17:13 - 2016-05-04 17:15 - 14572000 _____ (Microsoft Corporation) C:\Users\Casa\Downloads\vc_redist.x64.exe
2016-05-03 19:39 - 2016-05-03 19:39 - 03750018 _____ C:\Users\Casa\Downloads\content.rar
2016-05-03 19:18 - 2016-05-03 19:18 - 01735558 _____ C:\Users\Casa\Downloads\cemu_1.4.0 (2).zip
2016-05-03 18:44 - 2016-05-03 18:44 - 00000000 ____D C:\Users\Casa\Desktop\Emulador de Controle Tomb Raider - x360ce - Cópia
2016-05-03 18:04 - 2016-05-03 18:04 - 00000000 ____D C:\Users\Casa\Desktop\CemuMod Fusion Ver 1.0
2016-05-03 18:03 - 2016-05-03 18:03 - 00001015 _____ C:\Users\Casa\Downloads\Cemu 1.4.0 Fix Version 1.0 Luigui U por Inmortalgames (1).txt
2016-05-03 18:03 - 2016-04-30 20:11 - 00000028 _____ C:\Users\Casa\Desktop\serial.bin
2016-05-03 18:02 - 2016-05-03 18:03 - 10414123 _____ C:\Users\Casa\Downloads\CemuMod Fusion Ver 1.0.rar
2016-05-03 06:32 - 2016-05-03 06:32 - 00083796 _____ C:\Users\Casa\Downloads\Super.Mario.3D.World.USA.WiiU-PoWeRUp-7z.torrent
2016-05-02 17:04 - 2016-05-04 17:43 - 00002060 _____ C:\Users\Casa\Desktop\Google Chrome.lnk
2016-05-02 16:32 - 2016-05-02 16:32 - 01735558 _____ C:\Users\Casa\Downloads\cemu_1.4.0.zip
2016-05-02 16:22 - 2016-05-02 16:21 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-05-01 17:52 - 2016-05-01 17:52 - 07496523 _____ C:\Users\Casa\Downloads\58759762316322 (1).rar
2016-05-01 17:51 - 2016-05-01 18:15 - 00000000 ____D C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY
2016-05-01 17:51 - 2016-05-01 17:51 - 00024461 _____ C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY.torrent
2016-05-01 17:30 - 2016-05-01 17:30 - 00001015 _____ C:\Users\Casa\Downloads\Cemu 1.4.0 Fix Version 1.0 Luigui U por Inmortalgames.txt
2016-05-01 17:30 - 2016-05-01 17:30 - 00001008 _____ C:\Users\Casa\Downloads\Cemu 1.4.2 Version Oficial por Inmortalgames.txt
2016-04-30 17:31 - 2016-05-03 06:44 - 00000000 ____D C:\Users\Casa\Downloads\Shadow_Warrior-FLT
2016-04-30 17:19 - 2016-04-30 17:19 - 00023086 _____ C:\Users\Casa\Downloads\shadow-warrior-special-edition-multi11pcdvdprophet.torrent
2016-04-29 18:02 - 2016-04-29 18:35 - 00000000 ____D C:\Users\Casa\Downloads\Costume.Quest.v1.0.11.MacOSX.READNFO-EZGAME.www.GamesTorrents.com
2016-04-29 18:01 - 2016-04-29 18:01 - 00012048 _____ C:\Users\Casa\Downloads\costumequestv1011macosxreadnfo-ezgame[www.gamestorrent.biz] (1).torrent
2016-04-28 19:27 - 2016-04-28 19:27 - 00072851 _____ C:\Users\Casa\Downloads\COSTUME.QUEST.2.V1.0.ALL.RITUEL.NODVD.ZIP
2016-04-28 19:25 - 2016-04-28 19:26 - 00918688 _____ C:\Users\Casa\Downloads\d3dx9.zip
2016-04-28 18:15 - 2016-04-28 18:15 - 00012048 _____ C:\Users\Casa\Downloads\costumequestv1011macosxreadnfo-ezgame[www.gamestorrent.biz].torrent
2016-04-28 06:55 - 2016-04-28 06:55 - 00000000 ____D C:\Users\Casa\Downloads\Alan.Wake-SKIDROW
2016-04-27 19:14 - 2016-04-27 19:14 - 00000000 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (5).txt
2016-04-27 18:58 - 2016-04-27 18:58 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Doublefine
2016-04-27 17:46 - 2016-04-27 17:46 - 00000593 _____ C:\Users\Casa\Desktop\Cemu - Atalho.lnk
2016-04-27 17:40 - 2016-04-27 17:40 - 07496523 _____ C:\Users\Casa\Downloads\new super mario bros u fix.rar
2016-04-27 10:53 - 2016-04-27 10:53 - 00001724 _____ C:\Users\Casa\Downloads\Castlevania Lords Of Shadow 2 [MULTI6][PCDVD][Repack BlackBox][WwW.GamesTorrents.CoM] - Atalho.lnk
2016-04-27 10:53 - 2016-04-27 10:53 - 00001409 _____ C:\Users\Casa\Downloads\New Super Luigi U [EUR] MULTi8 Loadiine READY2PLAY - Atalho.lnk
2016-04-27 10:53 - 2016-04-27 10:53 - 00001391 _____ C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY - Atalho.lnk
2016-04-26 19:14 - 2016-04-27 18:51 - 980795931 ____R (Игры на Cat-A-Cat.NET ) C:\Users\Casa\Downloads\Costume Quest 2.exe
2016-04-26 16:39 - 2016-04-26 17:49 - 00000000 ____D C:\Users\Casa\Downloads\State.of.Decay-WaLMaRT
2016-04-26 06:45 - 2016-04-26 07:12 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 3 Temporada - The Pirate Filmes
2016-04-26 06:45 - 2016-04-26 07:03 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 2 Temporada - The Pirate Filmes
2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Todos os Usuários\.mono
2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Casa\AppData\Roaming\.mono
2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\ProgramData\.mono
2016-04-25 19:16 - 2016-04-25 19:16 - 00017483 _____ C:\Windows\DirectX.log
2016-04-25 18:37 - 2016-05-02 00:50 - 00000910 _____ C:\Users\Casa\Desktop\Novo Documento de Texto.txt
2016-04-25 05:34 - 2016-04-25 05:34 - 00039324 _____ C:\Users\Casa\Desktop\doença.htm
2016-04-24 18:40 - 2016-04-25 18:42 - 00000000 ____D C:\Program Files (x86)\Remedy Entertainment
2016-04-24 17:32 - 2016-04-24 17:33 - 00000000 ____D C:\Users\Casa\Desktop\Uma familia da pesada
2016-04-23 11:27 - 2016-04-23 11:27 - 00000000 ____D C:\Users\Casa\Documents\League of Legends
2016-04-23 08:38 - 2016-04-23 08:38 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-04-23 08:38 - 2016-04-23 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewFeature1
2016-04-23 08:37 - 2016-04-23 08:37 - 00000000 ____D C:\Users\Casa\Desktop\League of Legends
2016-04-22 19:45 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2016-04-22 19:45 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2016-04-22 19:45 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2016-04-22 19:44 - 2016-04-22 19:44 - 00000000 ____D C:\Riot Games
2016-04-22 16:18 - 2016-04-22 16:18 - 00000000 ____D C:\Users\Casa\Downloads\The.Walking.Dead.S06E01.PROPER.720p.HDTV.x264-KILLERS[rarbg]
2016-04-20 01:54 - 2016-04-20 02:10 - 00000000 ____D C:\Users\Casa\Downloads\Inatividade Paranormal (www.thePirateFilmes.com)
2016-04-19 06:54 - 2016-04-21 19:23 - 00000000 ____D C:\Users\Casa\Desktop\beelzebub
2016-04-19 06:43 - 2016-04-19 06:46 - 00000000 ____D C:\Users\Casa\Downloads\Inatividade Paranormal 2.(2014).Dublado.1080p.By.Luan.Harper
2016-04-16 18:29 - 2016-04-21 23:08 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 1 Temporada - The Pirate Filmes
2016-04-16 13:39 - 2016-04-16 13:39 - 00000408 _____ C:\Windows\Tasks\Overwolf Updater Task.job
2016-04-16 13:39 - 2016-04-16 13:39 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2016-04-16 13:39 - 2016-04-16 13:39 - 00000000 ____D C:\Program Files (x86)\Overwolf
2016-04-16 13:38 - 2016-04-16 13:39 - 00000000 ____D C:\Users\Todos os Usuários\Overwolf
2016-04-16 13:38 - 2016-04-16 13:39 - 00000000 ____D C:\ProgramData\Overwolf
2016-04-16 13:37 - 2016-04-30 09:13 - 00000000 ____D C:\Users\Casa\AppData\Roaming\TS3Client
2016-04-16 13:37 - 2016-04-16 13:44 - 00000000 ____D C:\Users\Casa\AppData\Local\Overwolf
2016-04-16 13:37 - 2016-04-16 13:37 - 00000967 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-04-16 13:37 - 2016-04-16 13:37 - 00000929 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2016-04-16 13:37 - 2016-04-16 13:37 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-04-15 09:59 - 2016-04-16 13:27 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
2016-04-14 19:29 - 2016-04-22 16:22 - 00000000 ____D C:\Users\Casa\Downloads\Uma.Aventura.Animal.na.Terra.do.Vento.2015.HDRip.XviD.Dublado-OSR
2016-04-14 12:10 - 2016-05-01 18:07 - 00000000 ____D C:\Users\Casa\Desktop\cemu_1.4.1
2016-04-14 12:10 - 2016-04-14 12:10 - 01742620 _____ C:\Users\Casa\Downloads\cemu_1.4.1.zip
2016-04-09 02:14 - 2016-04-09 02:37 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural - 10ª Temporada (2015) BluRay BDrip 720p Dual Áudio - HipnosTPF
2016-04-06 20:01 - 2016-04-24 19:18 - 00000000 ____D C:\Program Files (x86)\Dishonored

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-04 17:52 - 2015-03-03 10:40 - 01371832 _____ C:\Windows\WindowsUpdate.log
2016-05-04 17:17 - 2016-01-29 05:21 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
2016-05-04 17:17 - 2016-01-29 05:21 - 00000000 ____D C:\ProgramData\Package Cache
2016-05-04 17:17 - 2014-12-28 11:12 - 00000000 ____D C:\Users\Casa\AppData\Roaming\uTorrent
2016-05-04 07:21 - 2015-01-28 09:28 - 00000000 ____D C:\Users\Todos os Usuários\rvlkl
2016-05-04 07:21 - 2015-01-28 09:28 - 00000000 ____D C:\ProgramData\rvlkl
2016-05-04 06:45 - 2015-11-12 05:33 - 00000000 ____D C:\Program Files (x86)\Steam
2016-05-04 05:07 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-04 05:07 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-04 05:02 - 2015-03-22 16:22 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Skype
2016-05-04 04:59 - 2016-03-29 05:04 - 00012798 _____ C:\Windows\setupact.log
2016-05-03 18:15 - 2016-03-13 17:49 - 00000000 ____D C:\Users\Casa\Downloads\Super.Mario.3D.World.USA.WiiU-PoWeRUp-7z
2016-05-02 22:43 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\system32\NDF
2016-05-02 16:21 - 2016-02-19 18:24 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-01 22:35 - 2015-07-04 10:42 - 00000684 _____ C:\Users\Casa\Desktop\997027960.txt
2016-04-30 19:12 - 2015-11-25 03:22 - 00000000 ____D C:\Games
2016-04-30 18:51 - 2009-07-14 14:55 - 00709738 _____ C:\Windows\system32\prfh0416.dat
2016-04-30 18:51 - 2009-07-14 14:55 - 00149354 _____ C:\Windows\system32\prfc0416.dat
2016-04-30 18:51 - 2009-07-14 02:13 - 01647490 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-28 14:41 - 2014-12-27 17:11 - 00000000 ____D C:\Users\Casa
2016-04-28 14:39 - 2016-03-07 17:21 - 00000000 ____D C:\Users\paulo.Casa-PC
2016-04-28 14:39 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\registration
2016-04-27 17:41 - 2016-03-29 20:06 - 00000000 ____D C:\Users\Casa\Desktop\fairy tail
2016-04-25 19:43 - 2015-01-13 16:43 - 00000000 ____D C:\Users\Casa\Desktop\anderson freire
2016-04-25 19:31 - 2015-07-30 00:54 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-24 19:17 - 2016-02-23 18:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2016-04-24 19:17 - 2016-02-23 18:26 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics
2016-04-24 19:17 - 2015-09-30 18:02 - 00000000 ____D C:\Users\Casa\Documents\My Games
2016-04-24 19:17 - 2015-01-19 10:53 - 00000000 ____D C:\Users\Casa\AppData\Local\SKIDROW
2016-04-23 11:07 - 2015-07-31 14:07 - 00000000 ____D C:\Users\Casa\AppData\Roaming\LolClient
2016-04-22 19:46 - 2015-07-31 02:26 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Riot Games
2016-04-22 04:57 - 2014-12-28 10:24 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-15 14:29 - 2016-03-23 19:00 - 00000310 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (4).txt
2016-04-11 21:42 - 2015-09-22 19:25 - 00001954 _____ C:\Users\Casa\Desktop\RCGamebox.lnk
2016-04-05 19:09 - 2014-12-28 18:16 - 00000000 ____D C:\Users\Casa\AppData\Roaming\DAEMON Tools Lite

==================== Files in the root of some directories =======

2015-06-06 09:47 - 2015-06-06 09:53 - 0000183 _____ () C:\Program Files\Common Files\Novo Documento de Texto.txt
2015-05-18 16:32 - 2015-05-21 23:09 - 0000109 _____ () C:\Program Files (x86)\Common Files\Novo Documento de Texto.txt
2016-02-18 18:52 - 2016-02-18 18:52 - 7951360 _____ () C:\Users\Casa\AppData\Roaming\agent.dat
2015-06-16 01:16 - 2015-08-21 12:56 - 0000024 _____ () C:\Users\Casa\AppData\Roaming\appdataFr25.bin
2015-02-26 18:16 - 2015-05-14 23:36 - 0000020 _____ () C:\Users\Casa\AppData\Roaming\appdataFr3.bin
2016-02-18 18:52 - 2016-02-18 18:52 - 0054272 _____ () C:\Users\Casa\AppData\Roaming\ApplicationHosting.dat
2016-02-18 18:48 - 2016-02-18 18:49 - 0001344 _____ () C:\Users\Casa\AppData\Roaming\Bubble Dock.boostrap.log
2016-02-18 18:48 - 2016-02-18 18:48 - 0005707 _____ () C:\Users\Casa\AppData\Roaming\Bubble Dock.installation.log
2015-05-10 09:00 - 2015-05-10 09:00 - 0154283 ____H () C:\Users\Casa\AppData\Roaming\Casa-wchelper.dll
2016-02-18 18:52 - 2016-02-18 18:52 - 0063696 _____ () C:\Users\Casa\AppData\Roaming\Config.xml
2015-07-11 08:20 - 2016-02-24 12:38 - 0002725 _____ () C:\Users\Casa\AppData\Roaming\droid4xinstaller.log
2015-06-14 17:29 - 2015-06-14 17:29 - 1322672 _____ () C:\Users\Casa\AppData\Roaming\GameHouse-Installer_am-cuttherope_gamehouse_.exe
2016-02-18 18:49 - 2016-02-18 18:50 - 0016992 _____ () C:\Users\Casa\AppData\Roaming\InstallationConfiguration.xml
2016-02-18 18:49 - 2016-02-18 18:49 - 0126976 _____ () C:\Users\Casa\AppData\Roaming\Installer.dat
2015-04-14 13:28 - 2015-04-14 13:28 - 0001171 _____ () C:\Users\Casa\AppData\Roaming\Kx7lf0Ji0oXH
2015-04-20 11:05 - 2015-04-20 11:05 - 1246720 _____ () C:\Users\Casa\AppData\Roaming\Kx7lf0Ji0oXH.exe
2016-02-18 18:52 - 2016-02-18 18:52 - 0126464 _____ () C:\Users\Casa\AppData\Roaming\lobby.dat
2016-02-18 18:52 - 2016-02-18 18:52 - 0018432 _____ () C:\Users\Casa\AppData\Roaming\Main.dat
2016-02-18 18:52 - 2016-02-18 18:52 - 0005568 _____ () C:\Users\Casa\AppData\Roaming\md.xml
2015-06-14 17:30 - 2015-10-26 05:53 - 0400728 _____ () C:\Users\Casa\AppData\Roaming\msconfig.ini
2016-02-18 18:52 - 2016-02-18 18:52 - 0126464 _____ () C:\Users\Casa\AppData\Roaming\noah.dat
2016-02-18 18:52 - 2016-02-18 18:49 - 0667136 _____ () C:\Users\Casa\AppData\Roaming\Over-La.exe
2016-02-18 18:52 - 2016-02-18 18:52 - 1882213 _____ () C:\Users\Casa\AppData\Roaming\Over-La.tst
2016-02-18 18:49 - 2016-02-18 18:49 - 0000078 _____ () C:\Users\Casa\AppData\Roaming\Selection Tools.installation.log
2016-01-08 08:10 - 2016-01-08 08:10 - 0000001 _____ () C:\Users\Casa\AppData\Roaming\smw_inst
2016-02-18 18:52 - 2016-02-18 18:49 - 0667136 _____ () C:\Users\Casa\AppData\Roaming\TranKeylax.exe
2016-02-18 18:52 - 2016-02-18 18:52 - 0072777 _____ () C:\Users\Casa\AppData\Roaming\TranKeylax.tst
2016-02-18 18:51 - 2016-02-18 18:51 - 0848437 _____ () C:\Users\Casa\AppData\Roaming\Trustron.bin
2016-02-18 18:52 - 2016-02-18 18:52 - 0188584 _____ () C:\Users\Casa\AppData\Roaming\U-lux.bin
2016-02-18 18:53 - 2016-02-18 18:53 - 0032038 _____ () C:\Users\Casa\AppData\Roaming\uninstall_temp.ico
2015-03-30 10:25 - 2015-03-31 00:25 - 0000069 _____ () C:\Users\Casa\AppData\Roaming\WB.CFG
2016-02-18 18:48 - 2016-02-18 18:48 - 0000097 _____ () C:\Users\Casa\AppData\Roaming\WindApp.boostrap.log
2016-02-18 18:48 - 2016-02-18 18:49 - 0000078 _____ () C:\Users\Casa\AppData\Roaming\WindApp.installation.log
2015-01-18 09:07 - 2015-01-18 09:07 - 0000000 ___SH () C:\Users\Casa\AppData\Local\LumaEmu
2015-12-24 18:38 - 2015-12-24 18:38 - 0000017 _____ () C:\Users\Casa\AppData\Local\resmon.resmoncfg
2015-03-19 16:07 - 2015-04-22 08:17 - 0011662 _____ () C:\Users\Casa\AppData\Local\Temp-log.txt
2015-02-19 20:59 - 2015-02-19 20:59 - 0000227 _____ () C:\ProgramData\bc.ini

Files to move or delete:
====================
C:\Users\Casa\AppData\Roaming\msconfig.ini
C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job
C:\Windows\Tasks\{38AE8803-5DFC-46DC-B239-E31F33E05F68}.job
C:\Windows\Tasks\{DE2ABF7F-8BAB-4F89-BF73-1F181918DB64}.job


Some files in TEMP:
====================
C:\Users\Casa\AppData\Local\Temp\ICReinstall_American_McGee_s_Grimm_GOG_PC_FullDownGames.exe
C:\Users\Casa\AppData\Local\Temp\utils.dll
C:\Users\Casa\AppData\Local\Temp\ytd_sysmenu_setup.exe


Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\ahstock2a.dll

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-13 03:20

==================== End of log ============================

Publicité


Signaler le contenu de ce document

Publicité